Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-55197

26
FAUCET Score

CVE-2025-55197 is a high-severity denial-of-service vulnerability affecting pypdf versions prior to 6.0.0. An unauthenticated attacker can craft a malicious PDF file that, when read, exhausts the system's RAM, leading to service disruption. The vulnerability has a CVSS score of 7.5 and is easily exploitable with low attack complexity, requiring no user interaction. While no public exploits or active exploitation have been observed, the potential for a denial-of-service attack is significant. Organizations using affected pypdf versions should update to 6.0.0 or implement the provided workaround to mitigate this risk.

Impacted Technologies

VendorProductVersion(s)CPE
< 6.0.0CPE matchmatch criteria
cpe:2.3:a:pypdf_project:pypdf:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

6.6MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
UNREPORTED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.44%
Probability of exploitation in next 30 days
EPSS Percentile
35.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0044 is in the 15th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (19)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: pypdfFixed in: 6.0.0
redhatvendor investigatingvia redhat_api
Product: OpenShift LightspeedFixed in: openshift-lightspeed/lightspeed-service-api-rhel9
redhatvendor investigatingvia redhat_api
Product: OpenShift LightspeedFixed in: openshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-24/de-minimal-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-24/de-minimal-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-24/ee-supported-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-24/ee-supported-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-24/lightspeed-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-24/platform-resource-runner-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-25/aap-cloud-metrics-collector-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-25/ansible-dev-tools-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-25/de-minimal-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-25/de-minimal-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-25/ee-supported-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-25/ee-supported-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-25/lightspeed-chatbot-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-25/lightspeed-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-25/platform-resource-runner-rhel8

Vendor Advisories (2)

redhatCVE-2025-55197Moderate

pypdf: PyPDF RAM Exhaustion Vulnerability

Aug 13, 2025
pipGHSA-7hfw-26vp-jp8mmedium

PyPDF's Manipulated FlateDecode streams can exhaust RAM

Aug 13, 2025

References

github.com / py-pdf/pypdf/blob/0dd57738bbdcdb63f0fb43d8a6b3d222b6946595/pypdf/filters.py
Product
github.com / py-pdf/pypdf/issues/3429
Issue Tracking
github.com / py-pdf/pypdf/pull/3430
Patch
github.com / py-pdf/pypdf/releases/tag/6.0.0
Release Notes
github.com / py-pdf/pypdf/security/advisories/GHSA-7hfw-26vp-jp8m
MitigationThird Party Advisory