Infinite Loop Vulnerability in pypdf Library
CVE-2026-59936

8.7HIGH

Key Information:

Vendor

Py-PDF

Status
Vendor
CVE Published:
8 July 2026

What is CVE-2026-59936?

The pypdf library, a widely-used free and open-source PDF manipulation tool, is susceptible to a vulnerability that allows an attacker to create a specially crafted PDF file. This file may contain an improperly terminated inline image, resulting in an infinite loop during the inline image end marker detection process within the library. This condition can hinder normal operations, such as extracting text from the PDF pages. The issue has been resolved in version 6.14.1 of the library.

Affected Version(s)

pypdf < 6.14.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.