CVE-2025-66019

EUVD-2025-199017
pypdf is a free and open-source pure-python PDF library. Prior to version 6.4.0, an attacker who uses this vulnerability can craft a PDF which leads to a memory usage of up to 1 GB per stream. This requires parsing the content stream of a page using the LZWDecode filter. This issue has been patched in version 6.4.0.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 21%
Debian logo
Debian Releases
Debian Product
Codename
pypdf
bookworm
3.4.1-1+deb12u1
fixed
forky
5.4.0-1
fixed
sid
5.4.0-1
fixed
trixie
5.4.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pypdf
jammy
dne
noble
needs-triage
plucky
ignored
questing
needs-triage