All vulnerabilities

CVE-2026-59937

PyPI · pypdf

Summary

pypdf: Possible long runtimes for repeated malformed cross-reference entries

Advisory details

Impact

An attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires cross-reference streams with repeated malformed cross-reference streams.

Patches

This has been fixed in pypdf==6.14.0.

Workarounds

If you cannot upgrade yet, consider applying the changes from PR #3887.

References