Resource Exhaustion Vulnerability in pypdf Library by PyPDF
CVE-2026-48156

5.1MEDIUM

Key Information:

Vendor

Py-PDF

Status
Vendor
CVE Published:
28 May 2026

What is CVE-2026-48156?

The pypdf library, a popular free and open-source Python PDF handling tool, is susceptible to a resource exhaustion vulnerability in versions prior to 6.12.0. By crafting specially designed PDF files that leverage specific cross-reference streams and large /Size values, attackers can trigger excessively long runtimes, potentially leading to denial of service situations. This vulnerability has been addressed in the release of version 6.12.0, where mitigations were implemented to prevent such malicious exploitation.

Affected Version(s)

pypdf < 6.12.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.