CVE-2025-66019

pypdf is a free and open-source pure-python PDF library. Prior to version 6.4.0, an attacker who uses this vulnerability can craft a PDF which leads to a memory usage of up to 1 GB per stream. This requires parsing the content stream of a page using the LZWDecode filter. This issue has been patched in version 6.4.0.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
UNKNOWN
---
GitHub_MCNA
---
---
CISA-ADPADP
---
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 18%
Debian logo
Debian Releases
Debian Product
Codename
pypdf
bookworm
3.4.1-1+deb12u1
fixed
forky
5.4.0-1
fixed
sid
5.4.0-1
fixed
trixie
5.4.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pypdf
questing
needs-triage
plucky
needs-triage
noble
needs-triage
jammy
dne