CVE-2026-33699

EUVD-2026-16496
pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.2 have a vulnerability in which an attacker can craft a PDF which leads to an infinite loop. This requires reading a file in non-strict mode. This has been fixed in pypdf 6.9.2. If users cannot upgrade yet, consider applying the changes from the patch manually.
Infinite Loop
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 37.28%
Affected Products (NVD)
VendorProductVersion
pypdf_projectpypdf
𝑥
< 6.9.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pypdf
bookworm
no-dsa
forky
6.9.2-2
fixed
sid
6.9.2-2
fixed
trixie
no-dsa
pypdf2
bookworm
no-dsa
bullseye
postponed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pypdf
jammy
dne
noble
needs-triage
questing
ignored
resolute
needs-triage
pypdf2
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
dne
resolute
dne
xenial
ignored