The Python PDF library pypdf patched a denial-of-service vulnerability tracked as CVE-2026-59935 that can cause affected applications to hang while parsing crafted PDF files. The flaw affects versions earlier than 6.14.2 and is triggered by non-terminated inline images using ASCII85 or ASCIIHex filters, allowing a malicious PDF to drive the parser into an infinite loop during operations such as page text extraction.
The fix was merged in pull request #3892 and shipped in pypdf 6.14.2, where parsing logic was changed to raise PdfReadError on unexpected end-of-stream conditions instead of looping indefinitely. The associated commit also added regression tests for malformed inline image data, addressing a CWE-835 weakness and reducing the risk of resource exhaustion in systems that automatically process untrusted PDFs.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-08, CVE-2026-59935 was added for a pypdf vulnerability affecting versions earlier than 6.14.2. The flaw allows a malicious PDF with a non-terminated inline image using ASCII85 or ASCIIHex filters to trigger an infinite loop during parsing, causing a denial-of-service condition.
On 2026-06-23, pypdf released version 6.14.2, which includes the security fix for infinite loops caused by incomplete ASCII85 and ASCIIHex inline images. The release notes classify the change as a security item and reference pull request #3892.
On 2026-06-23, the pypdf project merged pull request #3892 and the associated commit to prevent infinite loops when parsing incomplete ASCII85 and ASCIIHex inline images. The change makes the parser raise PdfReadError on unexpected end-of-stream conditions and adds regression tests for malformed inline image data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.