{"id":"CVE-2025-62708","aliases":["GHSA-jfx9-29x2-rv3j","PYSEC-2026-1831"],"url":"https://o3.security/vulnerability/CVE-2025-62708","summary":"pypdf manipulated LZWDecode streams can exhaust RAM","details":"### Impact\n\nAn attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing the content stream of a page using the LZWDecode filter.\n\n### Patches\nThis has been fixed in [pypdf==6.1.3](https://github.com/py-pdf/pypdf/releases/tag/6.1.3).\n\n### Workarounds\nIf you cannot upgrade yet, consider applying the changes from PR [#3502](https://github.com/py-pdf/pypdf/pull/3502).","published":"2025-10-22T21:36:56.788Z","modified":"2026-08-12T03:51:12.168876766Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"pypdf","fixedVersion":"6.1.3"}],"fix":{"url":"https://github.com/py-pdf/pypdf/commit/e51d07807ffcdaf18077b9486dadb3dc05b368da","label":"py-pdf/pypdf@e51d078"},"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.1.3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/62xxx/CVE-2025-62708.json"},{"type":"ADVISORY","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-jfx9-29x2-rv3j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62708"},{"type":"FIX","url":"https://github.com/py-pdf/pypdf/commit/e51d07807ffcdaf18077b9486dadb3dc05b368da"},{"type":"FIX","url":"https://github.com/py-pdf/pypdf/pull/3502"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:12.168876766Z"}}