pypdf is a free and open-source pure-python PDF library. Prior to version 6.4.0, an attacker who uses this vulnerability can craft a PDF which leads to a memory usage of up to 1 GB per stream. This requires parsing the content stream of a page using the LZWDecode filter. This issue has been patched in version 6.4.0.
CVSS
No CVSS.
References
Configurations
No configuration.
History
26 Nov 2025, 00:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-26 00:15
Updated : 2025-11-26 00:15
NVD link : CVE-2025-66019
Mitre link : CVE-2025-66019
CVE.ORG link : CVE-2025-66019
JSON object : View
Products Affected
No product.
