GHSA-5qjq-93h5-hrgp

Suggest an improvement
Source
https://github.com/advisories/GHSA-5qjq-93h5-hrgp
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-5qjq-93h5-hrgp/GHSA-5qjq-93h5-hrgp.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-5qjq-93h5-hrgp
Aliases
Downstream
CGA (4)
MINI (9)
Published
2026-07-23T15:06:58Z
Modified
2026-08-04T14:40:33Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
pypdf: Possible large memory usage for wrong image dimensions
Details

Impact

An attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires loading images where the declared size values are much too large compared to the actual data.

Patches

This has been fixed in pypdf==6.14.0.

Workarounds

If you cannot upgrade yet, consider applying the changes from PR #3888.

Database specific
{
    "cwe_ids":  [
        "CWE-789"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-23T15:06:58Z",
    "nvd_published_at":  "2026-07-08T18:16:35Z",
    "severity":  "MODERATE"
}
References

Affected packages

PyPI / pypdf

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.14.0

Affected versions

1.*
1.0
1.1
1.2
1.3
1.4
1.5
1.6
1.7
1.8
1.9
1.10
1.11
1.12
1.13
3.*
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.12.2
3.13.0
3.14.0
3.15.0
3.15.1
3.15.2
3.15.3
3.15.4
3.15.5
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
4.*
4.0.0
4.0.1
4.0.2
4.1.0
4.2.0
4.3.0
4.3.1
5.*
5.0.0
5.0.1
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.5.0
5.6.0
5.6.1
5.7.0
5.8.0
5.9.0
6.*
6.0.0
6.1.0
6.1.1
6.1.2
6.1.3
6.2.0
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.6.0
6.6.1
6.6.2
6.7.0
6.7.1
6.7.2
6.7.3
6.7.4
6.7.5
6.8.0
6.9.0
6.9.1
6.9.2
6.10.0
6.10.1
6.10.2
6.11.0
6.12.0
6.12.1
6.12.2
6.13.0
6.13.1
6.13.2
6.13.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-5qjq-93h5-hrgp/GHSA-5qjq-93h5-hrgp.json"