Executive brief
A vulnerability has been identified in pypdf, a widely used Python library for manipulating PDF files. An attacker can provide a specially crafted PDF that, when processed or merged by the library, causes the application to enter an infinite loop. This results in a denial-of-service condition, making the affected application unresponsive and potentially consuming excessive system resources.
Technical details
A vulnerability classified as CWE-835 (Loop with Unreachable Exit Condition) exists in the pypdf library's writer component. The issue occurs when the library processes or merges PDF files containing specific thread or article structures, leading to an infinite loop. An attacker can exploit this by providing a malformed PDF file to an application that uses pypdf to merge or write PDF content. The attack is local in nature and requires no special privileges or user interaction beyond the processing of the file. The vulnerability is resolved in version 6.13.1.
Affected products
- py-pdf pypdf < 6.13.1
Timeline
- 2026-06-08: disclosed
- 2026-06-22: advisory: NVD publication date
- 2026-07-09: patched: GitHub Advisory published/updated