GHSA-8x2r-v9x5-3qgh

Suggest an improvement
Source
https://github.com/advisories/GHSA-8x2r-v9x5-3qgh
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-8x2r-v9x5-3qgh/GHSA-8x2r-v9x5-3qgh.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-8x2r-v9x5-3qgh
Withdrawn
2026-02-04T16:49:45Z
Published
2026-02-03T18:30:47Z
Modified
2026-02-04T17:34:58Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Duplicate Advisory: Insecure Deserialization (pickle) in pdfminer.six CMap Loader — Local Privesc
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-f83h-ghpp-7wcc. This link is maintained to preserve external references.

Original Description

pdfminer.six before 20251230 contains an insecure deserialization vulnerability in the CMap loading mechanism. The library uses Python pickle to deserialize CMap cache files without validation. An attacker with the ability to place a malicious pickle file in a location accessible to the application can trigger arbitrary code execution or privilege escalation when the file is loaded by a trusted process. This is caused by an incomplete patch to CVE-2025-64512.

Database specific
{
    "cwe_ids":  [
        "CWE-502"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-02-04T16:49:45Z",
    "nvd_published_at":  "2026-02-03T18:16:17Z",
    "severity":  "HIGH"
}
References

Affected packages

PyPI / pdfminer-six

Package

Name
pdfminer-six
View open source insights on deps.dev
Purl
pkg:pypi/pdfminer-six

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
20251230

Affected versions

Other
20140915
20151013
20160202
20160614
20170418
20170419
20170720
20181108
20191020
20191107
20191110
20200104
20200121
20200124
20200401
20200402
20200517
20200720
20200726
20201018
20211012
20220319
20220506
20220524
20221105
20231228
20240706
20250324
20250327
20250416
20250506
20251107
20251227
20251228
20251229

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-8x2r-v9x5-3qgh/GHSA-8x2r-v9x5-3qgh.json"