{"id":"CVE-2026-41314","aliases":["GHSA-x284-j5p8-9c5p","PYSEC-2026-3026"],"url":"https://o3.security/vulnerability/CVE-2026-41314","summary":"pypdf: Manipulated FlateDecode image dimensions can exhaust RAM","details":"pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to the RAM being exhausted. This requires accessing an image using `/FlateDecode` with large size values. This has been fixed in pypdf 6.10.2. As a workaround, one may apply the changes from the patch manually.","published":"2026-04-22T21:08:14.700Z","modified":"2026-07-15T01:48:57.652896155Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"pypdf","fixedVersion":"6.10.2"}],"fix":{"url":"https://github.com/py-pdf/pypdf/commit/ac734dab4eef92bcce50d503949b4d9887d89f11","label":"py-pdf/pypdf@ac734da"},"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.10.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41314.json"},{"type":"ADVISORY","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-x284-j5p8-9c5p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41314"},{"type":"FIX","url":"https://github.com/py-pdf/pypdf/commit/ac734dab4eef92bcce50d503949b4d9887d89f11"},{"type":"FIX","url":"https://github.com/py-pdf/pypdf/pull/3734"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:48:57.652896155Z"}}