debian · CVE-2026-59935

Quick triage

Priority: not yet assigned Published: Updated: Wed, 22 Jul 2026 14:46:41 GMT

View at Official debian advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2026-59935 not yet assigned priority: Debian including 2 source packages (pypdf, pypdf2), 6 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): open 6.

Description:

pypdf is a free and open-source pure-python PDF library. Prior to 6.14.2, an attacker can craft a PDF with a page content stream containing a not terminated inline image that uses the ASCII85 or ASCIIHex filters, causing an infinite loop during parsing such as when extracting page text. This issue is fixed in version 6.14.2.

cvelogic Threat Intelligence