Intel

AIKIDO-2025-10548

pypdf is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)CVE-2025-55197 Published Aug 13, 2025

50

Medium Risk

This Affects:

PYTHONpypdf
1.0 - 5.9.0
Fixed in 6.0.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to denial of service due to full decompression of nested FlateDecode streams, allowing a small malicious PDF to expand to over 1 PB and exhaust system resources.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

pypdf is vulnerable to Denial of Service (DoS) in versions 1.0 - 5.9.0.

How to fix this

Upgrade the pypdf library to the patch version.