Launch Week Day 1: Announcing Security Design Review
UNKNOWN PyPI

pypdf possibly has long runtimes for malformed FlateDecode streams

GHSA-9mvc-8737-8j8h · CVE-2026-27026

Published · Modified

Description

Impact

An attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires a malformed /FlateDecode stream, where the byte-by-byte decompression is used.

Patches

This has been fixed in pypdf==6.7.1.

Workarounds

If you cannot upgrade yet, consider applying the changes from PR #3644.

Ready to move

Start Securing

Free, no credit card | First findings in minutes