Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-57204

Опубликовано: 30 июн. 2026
Источник: debian

Описание

pypdf is a free and open-source pure-python PDF library. Prior to 6.13.3, a maliciously crafted PDF can cause DoS. An attacker who uses this vulnerability can craft a PDF which leads to large memory usage, as MAX_DECLARED_STREAM_LENGTH is sometimes ignored. This requires parsing a content stream without a /Length value. This issue has been fixed in version 6.13.3.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pypdfunfixedpackage
pypdfno-dsatrixiepackage
pypdfpostponedbookwormpackage
pypdf2removedpackage
pypdf2postponedbookwormpackage
pypdf2postponedbullseyepackage

Примечания

  • https://github.com/py-pdf/pypdf/security/advisories/GHSA-jm82-fx9c-mx94

  • https://github.com/py-pdf/pypdf/pull/3871

  • Fixed by: https://github.com/py-pdf/pypdf/commit/bbd083d1196d276d9c542418f77ac49e06de3ff1 (6.13.3)

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 месяца назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.13.3, a maliciously crafted PDF can cause DoS. An attacker who uses this vulnerability can craft a PDF which leads to large memory usage, as MAX_DECLARED_STREAM_LENGTH is sometimes ignored. This requires parsing a content stream without a /Length value. This issue has been fixed in version 6.13.3.

CVSS3: 6.5
redhat
около 1 месяца назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.13.3, a maliciously crafted PDF can cause DoS. An attacker who uses this vulnerability can craft a PDF which leads to large memory usage, as MAX_DECLARED_STREAM_LENGTH is sometimes ignored. This requires parsing a content stream without a /Length value. This issue has been fixed in version 6.13.3.

CVSS3: 6.5
nvd
около 1 месяца назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.13.3, a maliciously crafted PDF can cause DoS. An attacker who uses this vulnerability can craft a PDF which leads to large memory usage, as MAX_DECLARED_STREAM_LENGTH is sometimes ignored. This requires parsing a content stream without a /Length value. This issue has been fixed in version 6.13.3.