216.73.217.98

CVE-2026-41168

· Published 22/04/2026 21:17 · Modified 22/04/2026 21:23

Labels: CVE-2026-41168 2026-04-22CVE-2026-41168CWE-834[email protected]

Essential information

Published
22/04/2026 21:17
Modified
22/04/2026 21:23
Author
Creator
CVSS
6.9 MEDIUM (v3) 6.9 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.1 can craft a PDF which leads to long runtimes. This requires cross-reference streams with wrong large `/Size` values or object streams with wrong large `/N` values. This has been fixed in pypdf 6.10.1. As a workaround, one may apply the changes from the patch manually.

NVD status

Status
Undergoing Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
pypdf / pypdf cpe:2.3:a:pypdf:pypdf:<6.10.1:*:*:*:*:*:*:*

References