PT-2026-2244 · Pypi+2 · Pypdf+2

N0Zom1Z0

·

Published

2026-01-01

·

Updated

2026-04-17

·

CVE-2026-22690

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions pypdf versions prior to 6.6.0
Description pypdf is a free and open-source pure-python PDF library. Versions prior to 6.6.0 are susceptible to potential long runtimes when processing PDF files missing the /Root object but containing a large /Size value. An attacker can exploit this by creating a specially crafted PDF file that causes extended processing times, particularly in non-strict reading mode. This issue affects invalid files and can lead to a denial-of-service condition.
Recommendations Versions prior to 6.6.0 should be updated to version 6.6.0 or later.

Exploit

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2026-22690
GHSA-4XC4-762W-M6CG
OPENSUSE-SU-2026:10044-1

Affected Products

Debian
Red Os
Pypdf