CVE-2026-59938Medium▾ Sunlitpypdf: Possible large memory usage for wrong image dimensions
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 23.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.3%
0.3% → 0.5%
Last analysed / modified upstream
An attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires loading images where the declared size values are much too large compared to the actual data.
This has been fixed in pypdf==6.14.0.
If you cannot upgrade yet, consider applying the changes from PR #3888.
pypdf < 6.14.0Upgrade to a patched release:
pypdf 6.14.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-59937Mediumpypdf: Possible long runtimes for repeated malformed cross-reference entries
CVE-2026-82398Mediumpypdf is a free and open-source pure-python PDF library
CVE-2026-84309Mediumpypdf is a free and open-source pure-python PDF library
CVE-2026-84311Mediumpypdf is a free and open-source pure-python PDF library
CVE-2026-84310Mediumpypdf is a free and open-source pure-python PDF library
CVE-2026-71870Mediumpypdf is a free and open-source pure-python PDF library