LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-59935

pypdf project · pypdf

Published
CVSS7.5
Severityhigh
WeaknessCWE-835
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

pypdf is a free and open-source pure-python PDF library. Prior to 6.14.2, an attacker can craft a PDF with a page content stream containing a not terminated inline image that uses the ASCII85 or ASCIIHex filters, causing an infinite loop during parsing such as when extracting page text. This issue is fixed in version 6.14.2.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-59935

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-59935.