Resource Exhaustion Vulnerability in pypdf Library by PyPDF
CVE-2026-48156
5.1MEDIUM
What is CVE-2026-48156?
The pypdf library, a popular free and open-source Python PDF handling tool, is susceptible to a resource exhaustion vulnerability in versions prior to 6.12.0. By crafting specially designed PDF files that leverage specific cross-reference streams and large /Size values, attackers can trigger excessively long runtimes, potentially leading to denial of service situations. This vulnerability has been addressed in the release of version 6.12.0, where mitigations were implemented to prevent such malicious exploitation.
Affected Version(s)
pypdf < 6.12.0
