Denial of Service Vulnerability in pypdf Library by PyPDF
CVE-2026-41313

4.8MEDIUM

Key Information:

Vendor

Py-PDF

Status
Vendor
CVE Published:
22 April 2026

What is CVE-2026-41313?

The pypdf library, a free and open-source pure-Python tool for PDF manipulation, contains a vulnerability in versions prior to 6.10.2. This flaw allows an attacker to craft a malicious PDF file with an excessively large trailer /Size value, which can result in prolonged runtimes when the library attempts to process the PDF in incremental mode. To mitigate this issue, users are advised to upgrade to version 6.10.2 or manually apply the relevant patches.

Affected Version(s)

pypdf < 6.10.2

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.