CVE-2026-48156
MEDIUM
5,1
Source: [email protected]
Attack Vector: local
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
Description
AI Translation Available
pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires cross-reference streams with /W [0 0 0] values and large /Size values. This vulnerability is fixed in 6.12.0.
834
Excessive Iteration
IncompleteCommon Consequences
Security Scopes Affected:
Availability
Potential Impacts:
Dos: Resource Consumption (Cpu)
Dos: Resource Consumption (Memory)
Dos: Amplification
Dos: Crash, Exit, Or Restart
Applicable Platforms
All platforms may be affected
https://github.com/py-pdf/pypdf/pull/3791
https://github.com/py-pdf/pypdf/releases/tag/6.12.0
https://github.com/py-pdf/pypdf/security/advisories/GHSA-248m-82v9-q6g6