GHSA-5jq2-8x83-x246: Pip/pypdf vulnerability
Impact
An attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires reading a PDF document with long indirect object headers, not terminated by whitespace.
Patches
This has been fixed in pypdf==6.18.0.
Workarounds
If you cannot upgrade yet, consider applying the changes from PR #4055.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/pypdfto a version that resolves this vulnerability.Fixed in 6.18.0 - Upgrade
Upgrade
pypdfto a version that resolves this vulnerability.Fixed in 6.18.0
Event History
Frequently Asked Questions
Who is exposed to this issue?
Applications using pypdf to read attacker-controlled or otherwise untrusted PDF documents are exposed. Exploitation requires the application to process a PDF containing long indirect object headers that are not terminated by whitespace.
What is the practical impact of a malicious PDF?
A crafted PDF can cause long runtimes while it is being read, which can tie up processing resources and delay PDF-handling operations.
Which version fixes the issue?
The issue is fixed in pypdf 6.18.0.
What can be done if upgrading is not immediately possible?
Consider applying the changes from PR #4055 as a workaround.