Loading
Generated remediation guidance and an executive summary. No account required.
pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.1 allow an attacker to craft a malicious PDF which leads to long runtimes and/or large memory usage. Exploitation requires accessing an array-based stream with many entries. This issue has been fixed in version 6.9.1.
Use CWE-400, Pypdf Project vendor hub and Pypdf product page to widen CVE-2026-33123 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-41168, CVE-2026-40260 and CVE-2026-28804 for nearby disclosures in the same product family.