CVE-2026-41314 is a denial-of-service vulnerability in pypdf versions prior to 6.10.2 that allows attackers to craft malicious PDF files with specially crafted images using FlateDecode compression and large size values to exhaust system RAM. The vulnerability affects the open-source pypdf library, a pure-Python PDF processing tool used across various applications and environments. The attack requires direct file access or the ability to supply a crafted PDF to the application using pypdf. While CVSS scoring data is unavailable, the EPSS score of 0.00014 indicates minimal empirical exploitation probability, suggesting low real-world attack likelihood. The FAUCET Risk Score of 31.0/100 reflects moderate concern, primarily driven by the denial-of-service impact potential rather than widespread adoption of vulnerable versions. There is no evidence of active exploitation in the wild, as indicated by the absence from the Known Exploited Vulnerabilities (KEV) catalog and its inactive status on the Hot List. The vulnerability has been addressed in pypdf 6.10.2, and affected users can either upgrade or manually apply the published patch. Community attention appears limited given the low EPSS score and lack of public exploit availability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.10.2CPE matchmatch criteria | cpe:2.3:a:pypdf_project:pypdf:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.