logo

Database

Asymmetric denial of service - ReDoS In pypdf

Description

pypdf: Manipulated FlateDecode XFA streams can exhaust RAM

Impact

An attacker who uses this vulnerability can craft a PDF which leads to the RAM being exhausted. This requires accessing the xfa property of a reader or writer and the corresponding stream being compressed using /FlateDecode.

Patches

This has been fixed in pypdf==6.7.3.

Workarounds

If projects cannot upgrade yet, consider applying the changes from PR #3658.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions
FLAT-R4KSV – Vulnerability | Fluid Attacks Database