Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-28804

Опубликовано: 06 мар. 2026
Источник: debian

Описание

pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /ASCIIHexDecode filter. This issue has been patched in version 6.7.5.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pypdffixed6.9.0-1package
pypdfno-dsatrixiepackage
pypdfno-dsabookwormpackage
pypdf2removedpackage
pypdf2no-dsabookwormpackage
pypdf2postponedbullseyepackage

Примечания

  • https://github.com/py-pdf/pypdf/security/advisories/GHSA-9m86-7pmv-2852

  • https://github.com/py-pdf/pypdf/pull/3666

  • Fixed by: https://github.com/py-pdf/pypdf/commit/648c627d2657447dfb1773412af05a0a5103b98f (6.7.5)

Связанные уязвимости

CVSS3: 5.3
ubuntu
5 месяцев назад

pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /ASCIIHexDecode filter. This issue has been patched in version 6.7.5.

CVSS3: 6.5
redhat
5 месяцев назад

pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /ASCIIHexDecode filter. This issue has been patched in version 6.7.5.

CVSS3: 5.3
nvd
5 месяцев назад

pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /ASCIIHexDecode filter. This issue has been patched in version 6.7.5.

suse-cvrf
5 месяцев назад

Security update for python-PyPDF2

github
5 месяцев назад

pypdf vulnerable to inefficient decoding of ASCIIHexDecode streams