Infinite Loop Vulnerability in PDF Library by PyPDF
CVE-2026-54530

6.9MEDIUM

Key Information:

Vendor

Py-PDF

Status
Vendor
CVE Published:
22 June 2026

What is CVE-2026-54530?

The PyPDF library, an open-source pure-Python library for handling PDF files, contains a vulnerability that allows an attacker to craft a specially designed PDF file that triggers an infinite loop when text is extracted in layout mode. This behavior impacts system resources and can lead to denial of service. The issue has been addressed in version 6.13.0, which is crucial for users relying on the library for PDF manipulations. Users are encouraged to upgrade to the latest version to mitigate any potential risks.

Affected Version(s)

pypdf < 6.13.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.