Feed/CVE-2026-54651
CVE-2026-54651MEDIUMCVSS 0.0

pypdf: Possible infinite loop when processing threads/articles in writer

Published Jul 9, 2026·Updated Jul 9, 2026

NVD Description

### Impact An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with threads/articles into a writer. ### Patches This has been fixed in [pypdf==6.13.1](https://github.com/py-pdf/pypdf/releases/tag/6.13.1). ### Workarounds If users cannot upgrade yet, consider applying the changes from PR [#3839](https://github.com/py-pdf/pypdf/pull/3839).

Affected Packages (1)

pypdfPYPI
Fixed in 6.13.1

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free