PYSEC-2026-1832
pypdf's LZWDecode streams be manipulated to exhaust RAM
Quick fix
PYSEC-2026-1832 — pypdf: upgrade to the fixed version with the command below.
pip install --upgrade 'pypdf>=6.4.0'Details
### Impact
An attacker who uses this vulnerability can craft a PDF which leads to a memory usage of up to 1 GB per stream. This requires parsing the content stream of a page using the LZWDecode filter.
This is a follow up to [GHSA-jfx9-29x2-rv3j](https://github.com/py-pdf/pypdf/security/advisories/GHSA-jfx9-29x2-rv3j) to align the default limit with the one for *zlib*.
### Patches This has been fixed in [pypdf==6.4.0](https://github.com/py-pdf/pypdf/releases/tag/6.4.0).
### Workarounds If users cannot upgrade yet, use the line below to overwrite the default in their code:
```python pypdf.filters.LZW_MAX_OUTPUT_LENGTH = 75_000_000 ```
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/py-pdf/pypdf/security/advisories/GHSA-jfx9-29x2-rv3j[WEB]
- https://github.com/py-pdf/pypdf/security/advisories/GHSA-m449-cwjh-6pw7[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-66019[ADVISORY]
- https://github.com/py-pdf/pypdf/commit/96186725e5e6f237129a58a97cd19204a9ce40b2[WEB]
- https://aydinnyunus.github.io/2025/12/20/cve-2025-66019-pypdf-lzw-dos[WEB]
- https://github.com/py-pdf/pypdf[PACKAGE]
- https://github.com/py-pdf/pypdf/releases/tag/6.4.0[WEB]
- https://pypi.org/project/pypdf[PACKAGE]
- https://github.com/advisories/GHSA-m449-cwjh-6pw7[ADVISORY]