CVE-2026-33699
HIGHpypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_stream
Title source: cnaDescription
pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.2 have a vulnerability in which an attacker can craft a PDF which leads to an infinite loop. This requires reading a file in non-strict mode. This has been fixed in pypdf 6.9.2. If users cannot upgrade yet, consider applying the changes from the patch manually.
Scores
CVSS v3
7.5
EPSS
0.0002
EPSS Percentile
3.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-835
Status
published
Products (3)
py-pdf/pypdf
< 6.9.2
pypdf_project/pypdf
< 6.9.2
pypi/pypdf
0 - 6.9.2PyPI
Published
Mar 27, 2026
Tracked Since
Mar 27, 2026