{"id":"CVE-2023-36810","aliases":["GHSA-jrm6-h9cq-8gqw","PYSEC-2026-1837"],"title":"PyPDF2 quadratic runtime with malformed PDF missing xref marker","summary":"PyPDF2 quadratic runtime with malformed PDF missing xref marker","severity":"medium","cvss":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","vendor":"pypdf2","product":"pypdf2","ecosystem":"pip","affected":["pypdf2 < 1.27.9"],"patched":["pypdf2 1.27.9"],"published":"2023-06-30","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-jrm6-h9cq-8gqw","references":[{"url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-jrm6-h9cq-8gqw"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-36810"},{"url":"https://github.com/py-pdf/pypdf/issues/582"},{"url":"https://github.com/py-pdf/pypdf/pull/808"},{"url":"https://github.com/py-pdf/pypdf/commit/c6c56f550bb384e05f0139c796ba1308837d6373"},{"url":"https://github.com/py-pdf/pypdf"},{"url":"https://lists.debian.org/debian-lts-announce/2023/07/msg00019.html"}],"tags":["osv","pip"],"epss":0.0063,"epssPercentile":0.48825,"ingestedAt":"2026-07-08T18:25:50.882Z","slug":"CVE-2023-36810","body":"## Overview\n\n### Impact\nAn attacker who uses this vulnerability can craft a PDF which leads to unexpected long runtime.\nThis quadratic runtime blocks the current process and can utilize a single core of the CPU by 100%. It does not affect memory usage.\n\n### Patches\nhttps://github.com/py-pdf/pypdf/pull/808\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\n\n### References\n* [PyPDF2 PR #808](https://github.com/py-pdf/pypdf/pull/808)\n* [PyPDF2 Issue #582](https://github.com/py-pdf/pypdf/issues/582)\n\n## Affected packages\n\n- `pypdf2 < 1.27.9`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `pypdf2 1.27.9`","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":34.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}