CVE-2025-66019: Py-PDF Pypdf
Medium severity, CVSS 6.6. EPSS: 0.4% chance of exploitation in the next 30 days.
pypdf is a free and open-source pure-python PDF library. Prior to version 6.4.0, an attacker who uses this vulnerability can craft a PDF which leads to a memory usage of up to 1 GB per stream. This requires parsing the content stream of a page using the LZWDecode filter. This issue has been patched in version 6.4.0.
Affected products
- Py-PDF Pypdf: before 6.4.0 (fixed in 6.4.0)
Published 2025-11-26. Last modified 2026-06-17.