CVE-2026-22691

pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for malformed startxref. An attacker who uses this vulnerability can craft a PDF which leads to possibly long runtimes for invalid startxref entries. When rebuilding the cross-reference table, PDF files with lots of whitespace characters become problematic. Only the non-strict reading mode is affected. Only the non-strict reading mode is affected. This issue has been patched in version 6.6.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:pypdf_project:pypdf:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:20

Type Values Removed Values Added
References () https://github.com/py-pdf/pypdf/security/advisories/GHSA-4f6g-68pf-7vhv - Vendor Advisory, Mitigation () https://github.com/py-pdf/pypdf/security/advisories/GHSA-4f6g-68pf-7vhv - Mitigation, Vendor Advisory
Summary
  • (es) pypdf es una biblioteca PDF de Python puro, gratuita y de código abierto. Antes de la versión 6.6.0, pypdf presenta posibles tiempos de ejecución prolongados para 'startxref' malformados. Un atacante que utiliza esta vulnerabilidad puede crear un PDF que provoca posibles tiempos de ejecución prolongados para entradas 'startxref' no válidas. Al reconstruir la tabla de referencias cruzadas, los archivos PDF con muchos caracteres de espacio en blanco se vuelven problemáticos. Solo el modo de lectura no estricto se ve afectado. Solo el modo de lectura no estricto se ve afectado. Este problema ha sido parcheado en la versión 6.6.0.

22 Jan 2026, 15:01

Type Values Removed Values Added
References () https://github.com/py-pdf/pypdf/commit/294165726b646bb7799be1cc787f593f2fdbcf45 - () https://github.com/py-pdf/pypdf/commit/294165726b646bb7799be1cc787f593f2fdbcf45 - Patch
References () https://github.com/py-pdf/pypdf/pull/3594 - () https://github.com/py-pdf/pypdf/pull/3594 - Issue Tracking, Patch
References () https://github.com/py-pdf/pypdf/releases/tag/6.6.0 - () https://github.com/py-pdf/pypdf/releases/tag/6.6.0 - Release Notes
References () https://github.com/py-pdf/pypdf/security/advisories/GHSA-4f6g-68pf-7vhv - () https://github.com/py-pdf/pypdf/security/advisories/GHSA-4f6g-68pf-7vhv - Vendor Advisory, Mitigation
CPE cpe:2.3:a:pypdf_project:pypdf:*:*:*:*:*:*:*:*
First Time Pypdf Project
Pypdf Project pypdf
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3

10 Jan 2026, 05:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-10 05:16

Updated : 2026-06-17 10:20


NVD link : CVE-2026-22691

Mitre link : CVE-2026-22691

CVE.ORG link : CVE-2026-22691


JSON object : View

Products Affected

pypdf_project

  • pypdf
CWE
CWE-400

Uncontrolled Resource Consumption

CWE-1333

Inefficient Regular Expression Complexity