Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9m86-7pmv-2852

Опубликовано: 02 мар. 2026
Источник: github
Github: Прошло ревью
CVSS4: 6.9

Описание

pypdf vulnerable to inefficient decoding of ASCIIHexDecode streams

Impact

An attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /ASCIIHexDecode filter.

Patches

This has been fixed in pypdf==6.7.5.

Workarounds

If you cannot upgrade yet, consider applying the changes from PR #3666.

Пакеты

Наименование

pypdf

pip
Затронутые версииВерсия исправления

< 6.7.5

6.7.5

EPSS

Процентиль: 14%
0.00045
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-407

Связанные уязвимости

CVSS3: 5.3
ubuntu
21 день назад

pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /ASCIIHexDecode filter. This issue has been patched in version 6.7.5.

CVSS3: 6.5
redhat
21 день назад

pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /ASCIIHexDecode filter. This issue has been patched in version 6.7.5.

CVSS3: 5.3
nvd
21 день назад

pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /ASCIIHexDecode filter. This issue has been patched in version 6.7.5.

CVSS3: 5.3
debian
21 день назад

pypdf is a free and open-source pure-python PDF library. Prior to vers ...

suse-cvrf
16 дней назад

Security update for python-PyPDF2

EPSS

Процентиль: 14%
0.00045
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-407