CVE-2023-36810Medium· 6.2▾ SunlitPyPDF2 quadratic runtime with malformed PDF missing xref marker
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.6%
0.6% → 0.6%
An attacker who uses this vulnerability can craft a PDF which leads to unexpected long runtime. This quadratic runtime blocks the current process and can utilize a single core of the CPU by 100%. It does not affect memory usage.
https://github.com/py-pdf/pypdf/pull/808
Is there a way for users to fix or remediate the vulnerability without upgrading?
pypdf2 < 1.27.9Upgrade to a patched release:
pypdf2 1.27.9Connected by shared product, vendor, weakness, or advisory.