{"id":"CVE-2026-41313","aliases":["GHSA-4pxv-j86v-mhcw","PYSEC-2026-3007"],"url":"https://o3.security/vulnerability/CVE-2026-41313","summary":"pypdf: Possible long runtimes for wrong size values in incremental mode","details":"pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to long runtimes. This requires loading a PDF with a large trailer `/Size` value in incremental mode. This has been fixed in pypdf 6.10.2. As a workaround, one may apply the changes from the patch manually.","published":"2026-04-22T21:04:59.877Z","modified":"2026-07-15T01:49:10.655204852Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"pypdf","fixedVersion":"6.10.2"}],"fix":{"url":"https://github.com/py-pdf/pypdf/commit/c50a0104cf083356f7c7f5d61410466a57f5c88a","label":"py-pdf/pypdf@c50a010"},"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.10.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41313.json"},{"type":"ADVISORY","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-4pxv-j86v-mhcw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41313"},{"type":"FIX","url":"https://github.com/py-pdf/pypdf/commit/c50a0104cf083356f7c7f5d61410466a57f5c88a"},{"type":"FIX","url":"https://github.com/py-pdf/pypdf/pull/3735"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:10.655204852Z"}}