CVE-2026-41313 is a denial-of-service vulnerability in pypdf versions prior to 6.10.2 that allows attackers to craft malicious PDF files capable of causing extended processing times. The vulnerability is triggered when loading PDFs with abnormally large trailer /Size values in incremental mode, affecting the open-source pypdf library used for PDF manipulation. The attack requires low complexity, as an attacker simply needs to create a specially crafted PDF file with an inflated /Size parameter. While the CVSS score is not available, the extremely low EPSS score of 0.00014 and FAUCET Risk Score of 31.0/100 indicate minimal practical severity. The primary impact is a potential denial-of-service condition through resource exhaustion rather than data compromise or unauthorized access. There is no evidence of active exploitation in the wild, as the vulnerability does not appear on the CISA Known Exploited Vulnerabilities list and remains inactive on security tracking lists. The fix has been available since pypdf version 6.10.2, and users can either upgrade or manually apply the provided patch as a temporary workaround.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.10.2CPE matchmatch criteria | cpe:2.3:a:pypdf_project:pypdf:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.