Pypi · Pypdf · CVE-2026-41314
**Name of the Vulnerable Software and Affected Versions**
pypdf versions prior to 6.10.2
**Description**
A flaw in the pypdf library allows an attacker to craft a PDF file that causes RAM exhaustion, leading to a denial of service. This occurs when accessing an image using the `/FlateDecode` filter with excessively large size values.
**Recommendations**
Update to version 6.10.2.
As a temporary workaround, apply the changes from the patch manually.