CVE-2026-28804
pypdf <6.7.5 - DoS
Title source: llmDescription
pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /ASCIIHexDecode filter. This issue has been patched in version 6.7.5.
Scores
EPSS
0.0004
EPSS Percentile
12.7%
Classification
CWE
CWE-407
Status
draft
Affected Products (1)
pypi/pypdf
< 6.7.5PyPI
Timeline
Published
Mar 06, 2026
Tracked Since
Mar 06, 2026