High severity7.5OSV Advisory· Published Jul 8, 2026· Updated Jul 9, 2026
CVE-2026-59937
CVE-2026-59937
Description
pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with repeated malformed cross-reference streams that cause pypdf to spend long runtimes recovering broken cross-reference table entries. This issue is fixed in version 6.14.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pypdfPyPI | < 6.14.0 | 6.14.0 |
Affected products
8- osv-coords5 versionspkg:apk/chainguard/open-webuipkg:apk/wolfi/open-webuipkg:apk/chainguard/litellmpkg:rpm/opensuse/python-PyPDF2&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/python-pypdf&distro=openSUSE%20Tumbleweed
< 0.11.0-r6+ 4 more
- (no CPE)range: < 0.11.0-r6
- (no CPE)range: < 0.11.0-r6
- (no CPE)range: < 1.93.0-r3
- (no CPE)range: < 2.11.1-bp160.8.1
- (no CPE)range: < 6.14.2-1.1
Patches
Vulnerability mechanics
References
6- github.com/py-pdf/pypdf/commit/b5fc5aa714f4b696fb9b1deaa35a9e4a4eb50daenvdPatchWEB
- github.com/py-pdf/pypdf/pull/3887nvdIssue TrackingPatchWEB
- github.com/py-pdf/pypdf/security/advisories/GHSA-55h5-xmcq-c37vnvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-55h5-xmcq-c37vghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-59937ghsaADVISORY
- github.com/py-pdf/pypdf/releases/tag/6.14.0nvdProductRelease NotesWEB
News mentions
1- PyPDF: Three DoS Vulnerabilities Patched Together in Version 6.14.0Vypr Intelligence · Jul 9, 2026