CVE Database
/

CVE-2026-33123

Back to search

CVE-2026-33123

Published: Mar 20, 2026

Modified: Mar 20, 2026

PUBLISHED

Description

pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.1 allow an attacker to craft a malicious PDF which leads to long runtimes and/or large memory usage. Exploitation requires accessing an array-based stream with many entries. This issue has been fixed in version 6.9.1.

VendorProductVersions

py-pdf

pypdf

affected
< 6.9.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now