mediumVulnerability

GHSA-x284-j5p8-9c5p

### Impact An attacker who uses this vulnerability can craft a PDF which leads to the RAM being exhausted. This requires accessing an image using `/FlateDecode` with large size values. ### Patches This has been fixed in [pypdf==6.10.2](https://github.com/py-pdf/pypdf/releases/tag/6.10.2). ### Workarounds If you cannot upgrade yet, consider applying the changes from PR [#3734](https://github.com/py-pdf/pypdf/pull/3734).

Properties

ghsa_id
GHSA-x284-j5p8-9c5p
severity
medium
summary
pypdf: Manipulated FlateDecode image dimensions can exhaust RAM
cve_id
GHSA-x284-j5p8-9c5p
is_ghsa_only
true
ghsa_published
2026-04-16T21:30:25Z
source_url
https://github.com/advisories/GHSA-x284-j5p8-9c5p
ghsa_updated
2026-04-16T21:30:26Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]pip/pypdf

AFFECTS (1)

[Software]pip/pypdf

HAS_WEAKNESS (1)

[Weakness]Memory Allocation with Excessive Size Value

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-x284-j5p8-9c5p — Ninja Signal Threat Intelligence | Ninja Signal