Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-48156

Опубликовано: 28 мая 2026
Источник: debian
EPSS Низкий

Описание

pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires cross-reference streams with /W [0 0 0] values and large /Size values. This vulnerability is fixed in 6.12.0.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pypdfunfixedpackage
pypdfno-dsatrixiepackage
pypdfno-dsabookwormpackage
pypdf2removedpackage
pypdf2no-dsabookwormpackage
pypdf2postponedbullseyepackage

Примечания

  • https://github.com/py-pdf/pypdf/security/advisories/GHSA-248m-82v9-q6g6

  • https://github.com/py-pdf/pypdf/pull/3791

EPSS

Процентиль: 2%
0.00124
Низкий

Связанные уязвимости

CVSS3: 3.3
ubuntu
4 месяца назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires cross-reference streams with /W [0 0 0] values and large /Size values. This vulnerability is fixed in 6.12.0.

CVSS3: 3.3
redhat
4 месяца назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires cross-reference streams with /W [0 0 0] values and large /Size values. This vulnerability is fixed in 6.12.0.

CVSS3: 3.3
nvd
4 месяца назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires cross-reference streams with /W [0 0 0] values and large /Size values. This vulnerability is fixed in 6.12.0.

CVSS3: 4
redos
около 2 месяцев назад

Уязвимость python-PyPDF2

CVSS3: 4
redos
около 2 месяцев назад

Уязвимость python-PyPDF2

EPSS

Процентиль: 2%
0.00124
Низкий