GHSA-v247-6f48-mgcj: Pip/pypdf vulnerability
Impact
An attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing the embedded files through the dictionary-based API.
Patches
This has been fixed in pypdf==6.19.0.
Workarounds
If you cannot upgrade yet, consider applying the changes from PR #4081.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/pypdfto a version that resolves this vulnerability.Fixed in 6.19.0 - Upgrade
Upgrade
pypdfto a version that resolves this vulnerability.Fixed in 6.19.0 - Compensating control
If upgrading is not possible, apply the changes from PR #4081.
- Compensating control
Access embedded files through the dictionary-based API.
Event History
Frequently Asked Questions
What application behavior is exposed to this issue?
Applications that access PDF embedded files through pypdf's dictionary-based API are exposed when processing a crafted PDF. The reported impact is excessively long runtimes.
What does an attacker need to do to trigger the issue?
The attacker needs to provide a crafted PDF that is processed by code accessing embedded files through the dictionary-based API.
How can this be remediated or mitigated?
Upgrade to pypdf 6.19.0, which includes the fix. If upgrading is not immediately possible, apply the changes from PR #4081.