Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
6.9
pypdf PDFs Can Cause Slow Performance
CVE-2026-28804
GHSA-9m86-7pmv-2852
GHSA-9m86-7pmv-2852
Summary
A security issue in older versions of the pypdf library allows attackers to create a PDF that causes it to run slowly. This could impact performance, but not access sensitive data. Update to version 6.7.5 or later to fix the issue.
What to do
- Update pypdf to version 6.7.5.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| – | pypdf | <= 6.7.5 | 6.7.5 |
| pypdf_project | pypdf | <= 6.7.5 | – |
Original title
pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stre...
Original description
pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /ASCIIHexDecode filter. This issue has been patched in version 6.7.5.
nvd CVSS4.0
6.9
Vulnerability type
CWE-407
- https://github.com/advisories/GHSA-9m86-7pmv-2852
- https://github.com/py-pdf/pypdf/commit/648c627d2657447dfb1773412af05a0a5103b98f
- https://github.com/py-pdf/pypdf/pull/3666
- https://github.com/py-pdf/pypdf/releases/tag/6.7.5
- https://github.com/py-pdf/pypdf/security/advisories/GHSA-9m86-7pmv-2852
- https://nvd.nist.gov/vuln/detail/CVE-2026-28804
- https://github.com/py-pdf/pypdf Product
Published: 6 Mar 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026