Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-48156

Опубликовано: 28 мая 2026
Источник: nvd
CVSS3: 3.3
EPSS Низкий

Описание

pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires cross-reference streams with /W [0 0 0] values and large /Size values. This vulnerability is fixed in 6.12.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:pypdf_project:pypdf:*:*:*:*:*:*:*:*
Версия до 6.12.0 (исключая)

EPSS

Процентиль: 3%
0.00124
Низкий

3.3 Low

CVSS3

Дефекты

CWE-834

Связанные уязвимости

CVSS3: 3.3
ubuntu
2 месяца назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires cross-reference streams with /W [0 0 0] values and large /Size values. This vulnerability is fixed in 6.12.0.

CVSS3: 3.3
redhat
2 месяца назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires cross-reference streams with /W [0 0 0] values and large /Size values. This vulnerability is fixed in 6.12.0.

CVSS3: 3.3
debian
2 месяца назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.12 ...

CVSS3: 3.3
github
около 2 месяцев назад

pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streams

EPSS

Процентиль: 3%
0.00124
Низкий

3.3 Low

CVSS3

Дефекты

CWE-834