Skip to content

Possible long runtimes for repeated malformed cross-reference entries

Moderate
stefan6419846 published GHSA-55h5-xmcq-c37v Jun 22, 2026

Package

pip pypdf (pip)

Affected versions

< 6.14.0

Patched versions

>= 6.14.0

Description

Impact

An attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires cross-reference streams with repeated malformed cross-reference streams.

Patches

This has been fixed in pypdf==6.14.0.

Workarounds

If you cannot upgrade yet, consider applying the changes from PR #3887.

Severity

Moderate

CVE ID

CVE-2026-59937

Weaknesses

Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource. Learn more on MITRE.

Credits