CVE-2025-70559 Affecting pdfminer package, versions <20191020+dfsg-2ubuntu0.1~esm1


Severity

Recommended
medium

Based on Ubuntu security rating.

Threat Intelligence

EPSS
0.32% (24th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UBUNTU2004-PDFMINER-15204962
  • published25 Sept 2026
  • disclosed3 Feb 2026

Introduced: 3 Feb 2026

CVE-2025-70559  (opens in a new tab)

How to fix?

Upgrade Ubuntu:20.04 pdfminer to version 20191020+dfsg-2ubuntu0.1~esm1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream pdfminer package and not the pdfminer package as distributed by Ubuntu. See How to fix? for Ubuntu:20.04 relevant fixed versions and status.

pdfminer.six before 20251230 contains an insecure deserialization vulnerability in the CMap loading mechanism. The library uses Python pickle to deserialize CMap cache files without validation. An attacker with the ability to place a malicious pickle file in a location accessible to the application can trigger arbitrary code execution or privilege escalation when the file is loaded by a trusted process. This is caused by an incomplete patch to CVE-2025-64512.