Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-49460

Опубликовано: 22 июн. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /FlateDecode filter with a PNG predictor. This vulnerability is fixed in 6.12.2.

A flaw was found in pypdf (before 6.12.2). A crafted PDF that accesses a stream using the /FlateDecode filter with a PNG predictor can trigger excessively long processing times, leading to denial of service when the document is parsed.

Отчет

pypdf is vulnerable to denial of service when parsing a crafted PDF containing a /FlateDecode stream with a PNG predictor. An attacker who can supply such a document for processing may cause the application to hang on long runtimes. Red Hat exposure is in Python services that use pypdf for PDF ingestion, including Quay, OpenShift logging/observability tooling, and other containerized apps that bundle the library for document handling.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Not affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Not affected
OpenShift Lightspeedopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-chatbot-rhel8Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-cuda-rhel9Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-gaudi-rhel9Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-rocm-rhel9Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/disk-image-cuda-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-llama-stack-core-rhel9Not affected
Red Hat Quay 3quay/quay-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2491517pypdf: pypdf: Denial of Service via crafted PDF with FlateDecode filter

EPSS

Процентиль: 2%
0.00117
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
около 1 месяца назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /FlateDecode filter with a PNG predictor. This vulnerability is fixed in 6.12.2.

CVSS3: 3.3
nvd
около 1 месяца назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /FlateDecode filter with a PNG predictor. This vulnerability is fixed in 6.12.2.

CVSS3: 3.3
debian
около 1 месяца назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.12 ...

CVSS3: 4
redos
9 дней назад

Уязвимость python-PyPDF2

github
около 2 месяцев назад

pypdf: Inefficient decoding of FlateDecode PNG predictor streams

EPSS

Процентиль: 2%
0.00117
Низкий

5.5 Medium

CVSS3