VDB
Sign up
MEDIUM6.2

PYSEC-2026-1837

PyPDF2 quadratic runtime with malformed PDF missing xref marker

Quick fix

PYSEC-2026-1837 — pypdf2: upgrade to the fixed version with the command below.

pip install --upgrade 'pypdf2>=1.27.9'

Details

### Impact An attacker who uses this vulnerability can craft a PDF which leads to unexpected long runtime. This quadratic runtime blocks the current process and can utilize a single core of the CPU by 100%. It does not affect memory usage.

### Patches https://github.com/py-pdf/pypdf/pull/808

### Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_

### References * [PyPDF2 PR #808](https://github.com/py-pdf/pypdf/pull/808) * [PyPDF2 Issue #582](https://github.com/py-pdf/pypdf/issues/582)

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/pypdf2
Introduced in: 0Fixed in: 1.27.9
Fixpip install --upgrade 'pypdf2>=1.27.9'

References