Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-22691

Опубликовано: 10 янв. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for malformed startxref. An attacker who uses this vulnerability can craft a PDF which leads to possibly long runtimes for invalid startxref entries. When rebuilding the cross-reference table, PDF files with lots of whitespace characters become problematic. Only the non-strict reading mode is affected. Only the non-strict reading mode is affected. This issue has been patched in version 6.6.0.

A flaw was found in pypdf. A remote attacker can exploit this vulnerability by crafting a malicious PDF file with malformed startxref entries and excessive whitespace characters. This can cause excessively long processing times when rebuilding the cross-reference table in non-strict reading mode, leading to a denial of service.

Отчет

This vulnerability is rated MODERATE. The pypdf library, used in Red Hat Ansible Automation Platform, OpenShift Lightspeed, Red Hat Enterprise Linux AI, and Red Hat OpenShift AI, is susceptible to a denial of service when processing specially crafted PDF files in non-strict reading mode. An attacker could exploit this by providing a malicious PDF with malformed startxref entries and excessive whitespace, leading to prolonged processing times.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-service-api-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/de-minimal-rhel8Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/de-minimal-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/de-supported-rhel8Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/de-supported-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-minimal-rhel8Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-minimal-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-supported-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1050
https://bugzilla.redhat.com/show_bug.cgi?id=2428427pypdf: pypdf: Denial of Service via malformed PDF startxref entries

EPSS

Процентиль: 5%
0.00019
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for malformed startxref. An attacker who uses this vulnerability can craft a PDF which leads to possibly long runtimes for invalid startxref entries. When rebuilding the cross-reference table, PDF files with lots of whitespace characters become problematic. Only the non-strict reading mode is affected. Only the non-strict reading mode is affected. This issue has been patched in version 6.6.0.

CVSS3: 5.3
nvd
3 месяца назад

pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for malformed startxref. An attacker who uses this vulnerability can craft a PDF which leads to possibly long runtimes for invalid startxref entries. When rebuilding the cross-reference table, PDF files with lots of whitespace characters become problematic. Only the non-strict reading mode is affected. Only the non-strict reading mode is affected. This issue has been patched in version 6.6.0.

CVSS3: 5.3
debian
3 месяца назад

pypdf is a free and open-source pure-python PDF library. Prior to vers ...

github
3 месяца назад

pypdf has possible long runtimes for malformed startxref

EPSS

Процентиль: 5%
0.00019
Низкий

6.5 Medium

CVSS3