216.73.216.6

CVE-2026-41313

· Published 22/04/2026 22:16 · Modified 22/04/2026 22:16

Labels: CVE-2026-41313 2026-04-22CVE-2026-41313CWE-834[email protected]

Essential information

Published
22/04/2026 22:16
Modified
22/04/2026 22:16
Author
Creator
CVSS
4.8 MEDIUM (v3) 4.8 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to long runtimes. This requires loading a PDF with a large trailer `/Size` value in incremental mode. This has been fixed in pypdf 6.10.2. As a workaround, one may apply the changes from the patch manually.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
pypdf / pypdf cpe:2.3:a:pypdf:pypdf:<6.10.2:*:*:*:*:*:*:*

References