Infinite Loop Vulnerability in pypdf Library Affecting PDF Files
CVE-2026-54531

6.9MEDIUM

Key Information:

Vendor

Py-PDF

Status
Vendor
CVE Published:
22 June 2026

What is CVE-2026-54531?

The pypdf library, a popular open-source tool for handling PDF files in Python, contains a vulnerability that allows attackers to create crafted PDF files leading to an infinite loop during document processing. This issue occurs when merging files that include outlines, effectively causing the library to become unresponsive. The vulnerability has been addressed in version 6.13.0, where users are advised to upgrade to ensure their PDF processing activities remain secure.

Affected Version(s)

pypdf < 6.13.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.