VDB
Sign up
—

PYSEC-2026-1828

pypdf has possible long runtimes for malformed startxref

Quick fix

PYSEC-2026-1828 — pypdf: upgrade to the fixed version with the command below.

pip install --upgrade 'pypdf>=6.6.0'

Details

### Impact An attacker who exploits this vulnerability can craft a PDF which leads to possibly long runtimes for invalid `startxref` entries. When rebuilding the cross-reference table, PDF files with lots of whitespace characters become problematic. Only the non-strict reading mode is affected.

### Patches This has been fixed in [pypdf==6.6.0](https://github.com/py-pdf/pypdf/releases/tag/6.6.0).

### Workarounds

```python from pypdf import PdfReader, PdfWriter

# Instead of reader = PdfReader("file.pdf") # use the strict mode: reader = PdfReader("file.pdf", strict=True)

# Instead of writer = PdfWriter(clone_from="file.pdf") # use an explicit strict reader: writer = PdfWriter(clone_from=PdfReader("file.pdf", strict=True)) ```

### Resources This issue has been fixed in #3594.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/pypdf
Introduced in: 0Fixed in: 6.6.0
Fixpip install --upgrade 'pypdf>=6.6.0'

References