---
id: CVE-2026-22690
aliases:
  - GHSA-4xc4-762w-m6cg
  - PYSEC-2026-1829
title: >-
  pypdf has possible long runtimes for missing /Root object with large /Size
  values
summary: >-
  pypdf has possible long runtimes for missing /Root object with large /Size
  values
severity: low
vendor: pypdf
product: pypdf
ecosystem: pip
affected:
  - pypdf < 6.6.0
patched:
  - pypdf 6.6.0
published: '2026-01-09'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-4xc4-762w-m6cg'
references:
  - url: 'https://github.com/py-pdf/pypdf/security/advisories/GHSA-4xc4-762w-m6cg'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-22690'
  - url: 'https://github.com/py-pdf/pypdf/pull/3594'
  - url: >-
      https://github.com/py-pdf/pypdf/commit/294165726b646bb7799be1cc787f593f2fdbcf45
  - url: 'https://github.com/py-pdf/pypdf'
  - url: 'https://github.com/py-pdf/pypdf/releases/tag/6.6.0'
tags:
  - osv
  - pip
epss: 0.0044
epssPercentile: 0.37685
ingestedAt: '2026-07-08T18:25:45.724Z'
---

## Overview

### Impact
An attacker who exploits this vulnerability can craft a PDF which leads to possibly long runtimes for actually invalid files. This can be achieved by omitting the `/Root` entry in the trailer, while using a rather large `/Size` value. Only the non-strict reading mode is affected.

### Patches
This has been fixed in [pypdf==6.6.0](https://github.com/py-pdf/pypdf/releases/tag/6.6.0).

### Workarounds

```python
from pypdf import PdfReader, PdfWriter


# Instead of
reader = PdfReader("file.pdf")
# use the strict mode:
reader = PdfReader("file.pdf", strict=True)

# Instead of
writer = PdfWriter(clone_from="file.pdf")
# use an explicit strict reader:
writer = PdfWriter(clone_from=PdfReader("file.pdf", strict=True))
```

### Resources
This issue has been fixed in #3594.

## Affected packages

- `pypdf < 6.6.0`

## Remediation

Upgrade to a patched release:

- `pypdf 6.6.0`
