{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3apypdf_projectpypdf/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:pypdf_project:pypdf:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-59936"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["pypdf (\u003c 6.14.1)"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","vulnerability","python","library"],"_cs_type":"advisory","_cs_vendors":["pypdf"],"content_html":"\u003cp\u003eA high-severity denial of service (DoS) vulnerability, tracked as CVE-2026-59936, has been identified in the widely used Python library \u003ccode\u003epypdf\u003c/code\u003e. This vulnerability affects all \u003ccode\u003epypdf\u003c/code\u003e versions prior to 6.14.1. An attacker can exploit this flaw by crafting a specially malformed PDF document that contains a non-terminated inline image. When a vulnerable application or system attempts to parse the content stream of such a PDF, for example, during text extraction, the \u003ccode\u003epypdf\u003c/code\u003e library enters an uncontrolled infinite loop. This endless processing consumes excessive system resources, leading to the application becoming unresponsive and effectively causing a denial of service. The vulnerability was publicly disclosed on 2026-07-23 and a fix was released in \u003ccode\u003epypdf\u003c/code\u003e version 6.14.1. Organizations using \u003ccode\u003epypdf\u003c/code\u003e to process untrusted PDF inputs are at risk.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker crafts a malicious PDF document designed to exploit the \u003ccode\u003epypdf\u003c/code\u003e library.\u003c/li\u003e\n\u003cli\u003eThe crafted PDF incorporates a malformed, non-terminated inline image within one of its page content streams.\u003c/li\u003e\n\u003cli\u003eA target application or system processes this malicious PDF using a vulnerable version of the \u003ccode\u003epypdf\u003c/code\u003e library (e.g., any version prior to 6.14.1).\u003c/li\u003e\n\u003cli\u003eDuring a PDF operation such as text extraction, \u003ccode\u003epypdf\u003c/code\u003e attempts to parse the content stream containing the malformed inline image.\u003c/li\u003e\n\u003cli\u003eUpon encountering the improperly terminated inline image, the \u003ccode\u003epypdf\u003c/code\u003e parsing logic enters an infinite loop, continuously attempting to process the malformed data.\u003c/li\u003e\n\u003cli\u003eThis infinite loop leads to unchecked resource consumption (e.g., 100% CPU utilization), causing the application or system to hang or crash, resulting in a denial of service.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of CVE-2026-59936 results in a denial of service (DoS) condition. Any application or service that relies on the \u003ccode\u003epypdf\u003c/code\u003e library to process potentially untrusted PDF documents is at risk. If an attacker delivers a malicious PDF, the affected application will experience severe resource exhaustion, primarily high CPU usage, and will become unresponsive or crash. This can lead to significant operational disruptions, unavailability of critical services, and potential data loss if processes are abruptly terminated. Organizations handling user-submitted PDFs, such as document processing platforms, web forms, or content management systems, are particularly vulnerable to this type of attack.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade the \u003ccode\u003epypdf\u003c/code\u003e library to version \u003ccode\u003e6.14.1\u003c/code\u003e or newer to remediate \u003ccode\u003eCVE-2026-59936\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eIf upgrading to \u003ccode\u003epypdf\u003c/code\u003e version \u003ccode\u003e6.14.1\u003c/code\u003e is not immediately feasible, apply the specific code changes detailed in PR \u003ccode\u003e#3891\u003c/code\u003e as a temporary workaround for \u003ccode\u003eCVE-2026-59936\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eMonitor systems that process PDF documents using \u003ccode\u003epypdf\u003c/code\u003e for unusual spikes in CPU utilization or application unresponsiveness, which could indicate a denial of service attempt related to this vulnerability.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-23T16:39:59Z","date_published":"2026-07-23T16:39:59Z","id":"https://feed.craftedsignal.io/briefs/2026-07-pypdf-infinite-loop/","summary":"An attacker can exploit a vulnerability in the pypdf library by crafting a PDF containing a malformed, not terminated inline image. When this malicious PDF is processed by pypdf, such as during text extraction, it triggers an infinite loop, leading to a denial of service. The issue is resolved in pypdf version 6.14.1.","title":"pypdf: Possible infinite loop for not terminated inline images","url":"https://feed.craftedsignal.io/briefs/2026-07-pypdf-infinite-loop/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:pypdf_project:pypdf:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}