pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing the content stream of a page using the LZWDecode filter. This has been fixed in pypdf version 6.1.3.

Subscriptions

Vendors Products
Pypdf Project Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-jfx9-29x2-rv3j pypdf can exhaust RAM via manipulated LZWDecode streams
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 27 Oct 2025 20:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:pypdf_project:pypdf:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Thu, 23 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

threat_severity

Moderate


Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Pypdf Project
Pypdf Project pypdf
Vendors & Products Pypdf Project
Pypdf Project pypdf

Wed, 22 Oct 2025 21:45:00 +0000

Type Values Removed Values Added
Description pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing the content stream of a page using the LZWDecode filter. This has been fixed in pypdf version 6.1.3.
Title pypdf manipulated LZWDecode streams can exhaust RAM
Weaknesses CWE-409
References
Metrics cvssV4_0

{'score': 6.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-10-23T15:10:58.953Z

Reserved: 2025-10-20T19:41:22.739Z

Link: CVE-2025-62708

cve-icon Vulnrichment

Updated: 2025-10-23T15:10:50.231Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-22T22:15:35.880

Modified: 2025-10-27T20:24:06.390

Link: CVE-2025-62708

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-10-22T21:36:56Z

Links: CVE-2025-62708 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2025-10-23T09:58:44Z

Weaknesses