
CVE-2025-70559 pdfminer.six before 20251230 contains an insecure deserialization vulnerability in the CMap loading mechanism. The library uses Python pickle to deserialize CMap cach… https://www.cve.org/CVERecord?id=CVE-2025-70559
Post summary
The text reports an insecure deserialization vulnerability in pdfminer.six (before 20251230) using Python pickle in the CMap loading mechanism, but provides no PoC, exploit, patch, or evidence of active exploitation.
