Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-248m-82v9-q6g6

Опубликовано: 12 июн. 2026
Источник: github
Github: Прошло ревью
CVSS4: 5.1
CVSS3: 3.3

Описание

pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streams

Impact

An attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires cross-reference streams with /W [0 0 0] values and large /Size values.

Patches

This has been fixed in pypdf==6.12.0.

Workarounds

If developers are unable to upgrade their apps immediately, they should consider applying the changes from PR #3791.

Пакеты

Наименование

pypdf

pip
Затронутые версииВерсия исправления

< 6.12.0

6.12.0

EPSS

Процентиль: 3%
0.00124
Низкий

5.1 Medium

CVSS4

3.3 Low

CVSS3

Дефекты

CWE-834

Связанные уязвимости

CVSS3: 3.3
ubuntu
2 месяца назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires cross-reference streams with /W [0 0 0] values and large /Size values. This vulnerability is fixed in 6.12.0.

CVSS3: 3.3
redhat
2 месяца назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires cross-reference streams with /W [0 0 0] values and large /Size values. This vulnerability is fixed in 6.12.0.

CVSS3: 3.3
nvd
2 месяца назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires cross-reference streams with /W [0 0 0] values and large /Size values. This vulnerability is fixed in 6.12.0.

CVSS3: 3.3
debian
2 месяца назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.12 ...

EPSS

Процентиль: 3%
0.00124
Низкий

5.1 Medium

CVSS4

3.3 Low

CVSS3

Дефекты

CWE-834