Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4374-1 | pdfminer security update |
Debian DLA |
DLA-4374-2 | pdfminer security update |
Debian DSA |
DSA-6062-1 | pdfminer security update |
Github GHSA |
GHSA-wf5f-4jwr-ppcp | Arbitrary Code Execution in pdfminer.six via Crafted PDF Input |
Thu, 08 Jan 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 31 Dec 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Debian
Debian debian Linux |
|
| CPEs | cpe:2.3:a:pdfminer:pdfminer.six:*:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Debian
Debian debian Linux |
Wed, 19 Nov 2025 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 12 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Nov 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pdfminer
Pdfminer pdfminer.six |
|
| Vendors & Products |
Pdfminer
Pdfminer pdfminer.six |
Mon, 10 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pdfminer.six is a community maintained fork of the original PDFMiner, a tool for extracting information from PDF documents. Prior to version 20251107, pdfminer.six will execute arbitrary code from a malicious pickle file if provided with a malicious PDF file. The `CMapDB._load_data()` function in pdfminer.six uses `pickle.loads()` to deserialize pickle files. These pickle files are supposed to be part of the pdfminer.six distribution stored in the `cmap/` directory, but a malicious PDF can specify an alternative directory and filename as long as the filename ends in `.pickle.gz`. A malicious, zipped pickle file can then contain code which will automatically execute when the PDF is processed. Version 20251107 fixes the issue. | |
| Title | pdfminer.six vulnerable to Arbitrary Code Execution via Crafted PDF Input | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-08T22:04:11.704Z
Reserved: 2025-11-05T21:15:39.399Z
Link: CVE-2025-64512
Updated: 2026-01-08T22:04:11.704Z
Status : Modified
Published: 2025-11-10T22:15:40.067
Modified: 2026-01-08T22:16:02.240
Link: CVE-2025-64512
No data.
OpenCVE Enrichment
Updated: 2025-11-12T12:48:17Z
Debian DLA
Debian DSA
Github GHSA