{"id":"CVE-2025-55197","aliases":["GHSA-7hfw-26vp-jp8m","PYSEC-2026-1830"],"url":"https://o3.security/vulnerability/CVE-2025-55197","summary":"pypdf's Manipulated FlateDecode streams can exhaust RAM","details":"pypdf is a free and open-source pure-python PDF library. Prior to version 6.0.0, an attacker can craft a PDF which leads to the RAM being exhausted. This requires just reading the file if a series of FlateDecode filters is used on a malicious cross-reference stream. Other content streams are affected on explicit access. This issue has been fixed in 6.0.0. If an update is not possible, a workaround involves including the fixed code from pypdf.filters.decompress into the existing filters file.","published":"2025-08-13T23:03:02.018Z","modified":"2026-08-27T14:10:52.003281780Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"pypdf","fixedVersion":"6.0.0"}],"fix":{"url":"https://github.com/py-pdf/pypdf/pull/3430","label":"py-pdf/pypdf#3430"},"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/blob/0dd57738bbdcdb63f0fb43d8a6b3d222b6946595/pypdf/filters.py#L72-L143"},{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.0.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/55xxx/CVE-2025-55197.json"},{"type":"ADVISORY","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-7hfw-26vp-jp8m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-55197"},{"type":"REPORT","url":"https://github.com/py-pdf/pypdf/issues/3429"},{"type":"FIX","url":"https://github.com/py-pdf/pypdf/pull/3430"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T14:10:52.003281780Z"}}