CVE-2026-33123

Severity CVSS v4.0:
MEDIUM
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
20/03/2026
Last modified:
23/03/2026

Description

pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.1 allow an attacker to craft a malicious PDF which leads to long runtimes and/or large memory usage. Exploitation requires accessing an array-based stream with many entries. This issue has been fixed in version 6.9.1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pypdf_project:pypdf:*:*:*:*:*:*:*:* 6.9.1 (excluding)