#VU125806 Resource exhaustion in PyPDF - CVE-2025-55197
Published: April 10, 2026
PyPDF
Pypdf Project
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in FlateDecode stream processing when parsing a crafted PDF file. A remote attacker can supply a PDF with a malicious cross-reference stream using a series of FlateDecode filters to cause a denial of service.
Simply reading the file is sufficient for exploitation through a malicious cross-reference stream, while other content streams are affected on explicit access.