CVE List

CVE-2026-31826

Moderate 5.5

pypdf is a free and open-source pure-python PDF library. Prior to 6.8.0, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing a content stream with a rather large /Length value, regardless of the actual data length inside the stream. This vulnerability is fixed in 6.8.0.

Published March 10, 2026.

Affected software

Get alerts for Pypdf Project Pypdf

Reference links