Excessive Iteration in PyPDF - #VU132046
Published: May 21, 2026
PyPDF
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to excessive iteration in cross-reference stream processing when parsing a crafted PDF file. A remote attacker can supply a PDF with zero-only width values and a large size value to cause a denial of service.
Exploitation requires cross-reference streams with /W [0 0 0] values and large /Size values.