CVE-2026-84311

⚪ Do wiadomości

W pypdf przed wersją 6.16.1 atakujący może spowodować nadmierne zużycie pamięci przez PDF.

CVSS
3.3
EPSS
0.2%
Exploit
none
Vendor
pypdf_project
Opis źródłowy (NVD)

pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_page.py PageObject._extract_text and PageObject.extract_xform_text to traverse a directed acyclic graph of reused form XObjects in which each form invokes a child multiple times, creating exponentially many traversal paths and causing long runtimes and large memory consumption. This issue is fixed in version 6.16.1.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS3.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2026-09-01 21:18:46 UTC
Ostatnia modyfikacja (NVD)2026-10-05 17:42:45 UTC
Referencje