Aller au contenu

Fiche vulnérabilité

CVE-2026-59937 : faille élevée pypdf project pypdf (CVSS 7.5)

Description

pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with repeated malformed cross-reference streams that cause pypdf to spend long runtimes recovering broken cross-reference table entries. This issue is fixed in version 6.14.0.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitation active
Non signalée par la CISA
Publication
8 juil. 2026
Dernière mise à jour
9 juil. 2026

Produits concernés

  • pypdf project pypdf

Références

Rechercher une autre vulnérabilité dans la base CVE