Infinite Loop Vulnerability in pypdf Library by py-pdf
CVE-2026-59935

8.7HIGH

Key Information:

Vendor

Py-PDF

Status
Vendor
CVE Published:
8 July 2026

What is CVE-2026-59935?

The pypdf library, an open-source pure-Python PDF manipulation tool, is susceptible to an infinite loop vulnerability. Attackers can exploit this flaw by crafting a malicious PDF file containing an improperly terminated inline image using either the ASCII85 or ASCIIHex filters. This parsing error occurs during text extraction on pages containing such malformed content. The issue has been resolved in version 6.14.2 of the library, which users are encouraged to upgrade to in order to mitigate potential security risks.

Affected Version(s)

pypdf < 6.14.2

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.