Denial of Service Vulnerability in pypdf Library by PyPDF
CVE-2026-41168

6.9MEDIUM

Key Information:

Vendor

Py-PDF

Status
Vendor
CVE Published:
22 April 2026

What is CVE-2026-41168?

The pypdf library, a widely used open-source PDF manipulation tool, contains a vulnerability that allows attackers to create specially crafted PDF files. These files can cause excessive runtimes when processed by vulnerable versions of pypdf, specifically those prior to 6.10.1. The issue arises from improperly handled cross-reference streams with incorrect large /Size values or object streams exceeding safe limits on /N values. Users are encouraged to update to pypdf version 6.10.1 or apply the necessary patch manually to mitigate this issue.

Affected Version(s)

pypdf < 6.10.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.