216.73.217.22

CVE-2026-28804

· Published 06/03/2026 07:16 · Modified 06/03/2026 07:16

Labels: CVE-2026-28804 2026-03-06CVE-2026-28804CWE-407[email protected]

Essential information

Published
06/03/2026 07:16
Modified
06/03/2026 07:16
Author
Creator
CVSS
6.9 MEDIUM (v3) 6.9 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /ASCIIHexDecode filter. This issue has been patched in version 6.7.5.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
pypdf / pypdf cpe:2.3:a:pypdf:pypdf:<6.7.5:*:*:*:*:*:*:*

References