Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-54531

Опубликовано: 22 июн. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with outlines into a writer. This vulnerability is fixed in 6.13.0.

A flaw was found in pypdf (before 6.13.0). A crafted PDF with outlines can trigger an infinite loop when merged into a PdfWriter, causing denial of service.

Отчет

pypdf is vulnerable to denial of service via infinite loop when merging a crafted PDF with outlines into a PdfWriter. An attacker who can supply such a document for merge processing may hang the application indefinitely. Red Hat exposure mirrors other pypdf consumers: Python services that merge or rewrite PDFs using the library in Quay, observability, and hybrid platform containers.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Not affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Not affected
OpenShift Lightspeedopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-chatbot-rhel8Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-cuda-rhel9Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-gaudi-rhel9Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-rocm-rhel9Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/disk-image-cuda-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-llama-stack-core-rhel9Not affected
Red Hat Quay 3quay/quay-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2491524pypdf: pypdf: Denial of Service via crafted PDF with outlines

EPSS

Процентиль: 2%
0.00121
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 1 месяца назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with outlines into a writer. This vulnerability is fixed in 6.13.0.

CVSS3: 5.5
nvd
около 1 месяца назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with outlines into a writer. This vulnerability is fixed in 6.13.0.

CVSS3: 5.5
debian
около 1 месяца назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.13 ...

CVSS3: 6.2
redos
7 дней назад

Уязвимость python-PyPDF2

github
около 2 месяцев назад

pypdf: Possible infinite loop when processing outlines/bookmarks in writer

EPSS

Процентиль: 2%
0.00121
Низкий

5.5 Medium

CVSS3

Уязвимость CVE-2026-54531