pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires parsing the content stream of a page which has an inline image using the DCTDecode filter. This has been fixed in pypdf version 6.1.3.
History

Fri, 24 Oct 2025 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

threat_severity

Moderate


Thu, 23 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Pypdf Project
Pypdf Project pypdf
Vendors & Products Pypdf Project
Pypdf Project pypdf

Wed, 22 Oct 2025 21:45:00 +0000

Type Values Removed Values Added
Description pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires parsing the content stream of a page which has an inline image using the DCTDecode filter. This has been fixed in pypdf version 6.1.3.
Title pypdf affected by possible infinite loop when reading DCT inline images without EOF marker
Weaknesses CWE-834
References
Metrics cvssV4_0

{'score': 6.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-10-22T21:36:32.754Z

Updated: 2025-10-23T15:41:41.081Z

Reserved: 2025-10-20T19:41:22.739Z

Link: CVE-2025-62707

cve-icon Vulnrichment

Updated: 2025-10-23T15:41:36.895Z

cve-icon NVD

Status : Received

Published: 2025-10-22T22:15:35.707

Modified: 2025-10-22T22:15:35.707

Link: CVE-2025-62707

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-10-22T21:36:32Z

Links: CVE-2025-62707 - Bugzilla