Excessive Iteration in PyPDF - CVE-2025-62707
Published: February 12, 2026
Vulnerability identifier: #VU122773
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-62707
CWE-ID: CWE-834
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to excessive iteration. A remote attacker can craft a PDF which leads to an infinite loop. This requires parsing the content stream of a page which has an inline image using the DCTDecode filter.
Affected software
PyPDF
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
How to mitigate CVE-2025-62707
Install updates from vendor's website.
PyPDF - update to 6.1.3
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.0