Medium severity5.3OSV Advisory· Published Jul 8, 2026· Updated Jul 9, 2026
CVE-2026-59938
CVE-2026-59938
Description
pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with declared image size values that are much too large compared to the actual data, causing large memory usage in pypdf image parsing. This issue is fixed in version 6.14.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pypdfPyPI | < 6.14.0 | 6.14.0 |
Affected products
6- osv-coords3 versions
< 1.93.0-r3+ 2 more
- (no CPE)range: < 1.93.0-r3
- (no CPE)range: < 0.11.0-r6
- (no CPE)range: < 0.11.0-r6
Patches
Vulnerability mechanics
References
6- github.com/py-pdf/pypdf/commit/c64583be16b8e8763d8777075f8ecbf382014b7anvdPatchWEB
- github.com/py-pdf/pypdf/pull/3888nvdIssue TrackingPatchWEB
- github.com/py-pdf/pypdf/security/advisories/GHSA-5qjq-93h5-hrgpnvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-5qjq-93h5-hrgpghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-59938ghsaADVISORY
- github.com/py-pdf/pypdf/releases/tag/6.14.0nvdProductRelease NotesWEB
News mentions
1- PyPDF: Three DoS Vulnerabilities Patched Together in Version 6.14.0Vypr Intelligence · Jul 9, 2026