Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-28804

Опубликовано: 06 мар. 2026
Источник: debian
EPSS Низкий

Описание

pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /ASCIIHexDecode filter. This issue has been patched in version 6.7.5.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pypdffixed6.9.0-1package
pypdf2removedpackage

Примечания

  • https://github.com/py-pdf/pypdf/security/advisories/GHSA-9m86-7pmv-2852

  • https://github.com/py-pdf/pypdf/pull/3666

  • Fixed by: https://github.com/py-pdf/pypdf/commit/648c627d2657447dfb1773412af05a0a5103b98f (6.7.5)

EPSS

Процентиль: 14%
0.00045
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
21 день назад

pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /ASCIIHexDecode filter. This issue has been patched in version 6.7.5.

CVSS3: 6.5
redhat
21 день назад

pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /ASCIIHexDecode filter. This issue has been patched in version 6.7.5.

CVSS3: 5.3
nvd
21 день назад

pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /ASCIIHexDecode filter. This issue has been patched in version 6.7.5.

suse-cvrf
16 дней назад

Security update for python-PyPDF2

github
25 дней назад

pypdf vulnerable to inefficient decoding of ASCIIHexDecode streams

EPSS

Процентиль: 14%
0.00045
Низкий
Уязвимость CVE-2026-28804