CVE-2026-59935 HIGH

CVE-2026-59935: pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)

Vendor Py-Pdf
Product pypdf
Weakness CWE-835
Published July 8, 2026
Last update July 8, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

pypdf is a free and open-source pure-python PDF library. Prior to 6.14.2, an attacker can craft a PDF with a page content stream containing a not terminated inline image that uses the ASCII85 or ASCIIHex filters, causing an infinite loop during parsing such as when extracting page text. This issue is fixed in version 6.14.2.

Key dates

02Disclosure timeline

July 8, 2026 CVE published