216.73.217.50

CVE-2026-57204

· Published 01/07/2026 00:16 · Author: The MITRE Corporation

Labels: CVE-2026-57204

Essential information

Published
01/07/2026 00:16
Modified
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
6.9 MEDIUM (v4.0)
CISA KEV
No
CWE
CWE-400
CVSS vector

CVSS metrics

Description

pypdf is a free and open-source pure-python PDF library. Prior to 6.13.3, a maliciously crafted PDF can cause DoS. An attacker who uses this vulnerability can craft a PDF which leads to large memory usage, as MAX_DECLARED_STREAM_LENGTH is sometimes ignored. This requires parsing a content stream without a /Length value. This issue has been fixed in version 6.13.3.

NVD status

NVD
View on NVD