CVE-2026-49460
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Jun 22, 2026
Vendor
unknown
Description
pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /FlateDecode filter with a PNG predictor. This vulnerability is fixed in 6.12.2.