PT-2026-26191 · Pypi+1 · Pypdf+1

Kule500

·

Published

2026-01-01

·

Updated

2026-05-21

·

CVE-2026-33123

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions pypdf versions prior to 6.9.1
Description pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.1 allow an attacker to create a malicious PDF that can cause prolonged runtimes and/or significant memory usage. Exploitation requires accessing an array-based stream containing numerous entries. The issue has been addressed in version 6.9.1.
Recommendations Upgrade to pypdf version 6.9.1 or later.

Exploit

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2026-07265
CVE-2026-33123
GHSA-QPXP-75PX-XJCP
OPENSUSE-SU-2026:10402-1
OPENSUSE-SU-2026:10403-1
OPENSUSE-SU-2026:20430-1

Affected Products

Red Os
Pypdf