mediumVulnerability

GHSA-7gw9-cf7v-778f

### Impact An attacker who uses this vulnerability can craft a PDF which leads to the RAM being exhausted. This requires accessing a stream compressed using `/FlateDecode` with a `/Predictor` unequal 1 and large predictor parameters. ### Patches This has been fixed in [pypdf==6.10.2](https://github.com/py-pdf/pypdf/releases/tag/6.10.2). ### Workarounds If you cannot upgrade yet, consider applying the changes from PR [#3734](https://github.com/py-pdf/pypdf/pull/3734).

Properties

ghsa_id
GHSA-7gw9-cf7v-778f
severity
medium
summary
pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM
cve_id
GHSA-7gw9-cf7v-778f
is_ghsa_only
true
ghsa_published
2026-04-16T21:30:00Z
source_url
https://github.com/advisories/GHSA-7gw9-cf7v-778f
ghsa_updated
2026-04-16T21:30:01Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]pip/pypdf

AFFECTS (1)

[Software]pip/pypdf

HAS_WEAKNESS (1)

[Weakness]Memory Allocation with Excessive Size Value

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-7gw9-cf7v-778f — Ninja Signal Threat Intelligence | Ninja Signal