pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.1 can craft a PDF which leads to long runtimes. This requires cross-reference streams with wrong large `/Size` values or object streams with wrong large `/N` values. This has been fixed in pypdf 6.10.1. As a workaround, one may apply the changes from the patch manually.
Metrics
Affected Vendors & Products
References
History
Wed, 22 Apr 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.1 can craft a PDF which leads to long runtimes. This requires cross-reference streams with wrong large `/Size` values or object streams with wrong large `/N` values. This has been fixed in pypdf 6.10.1. As a workaround, one may apply the changes from the patch manually. | |
| Title | pypdf has possible long runtimes for wrong size values in cross-reference and object streams | |
| Weaknesses | CWE-834 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-22T20:49:10.401Z
Reserved: 2026-04-17T16:34:45.525Z
Link: CVE-2026-41168
No data.
Status : Awaiting Analysis
Published: 2026-04-22T21:17:09.450
Modified: 2026-04-22T21:23:52.620
Link: CVE-2026-41168
No data.
OpenCVE Enrichment
No data.