#1138193 pypdf: CVE-2026-48156

Package:
src:pypdf
Source:
src:pypdf
Submitter:
Salvatore Bonaccorso
Date:
2026-09-30 12:21:04 UTC
Severity:
normal
Tags:
#1138193#5
Date:
2026-05-29 06:55:07 UTC
From:
To:
Hi,

The following vulnerability was published for pypdf.

CVE-2026-48156[0]:
| pypdf is a free and open-source pure-python PDF library. Prior to
| 6.12.0, an attacker who uses this vulnerability can craft a PDF
| which leads to long runtimes. This requires cross-reference streams
| with /W [0 0 0] values and large /Size values. This vulnerability is
| fixed in 6.12.0.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-48156
https://www.cve.org/CVERecord?id=CVE-2026-48156
[1] https://github.com/py-pdf/pypdf/pull/3791
[2] https://github.com/py-pdf/pypdf/security/advisories/GHSA-248m-82v9-q6g6

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1138193#12
Date:
2026-09-30 12:19:10 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
pypdf, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1138193@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Pieter Lenaerts <plenae@disroot.org> (supplier of updated pypdf package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 29 Sep 2026 22:40:33 +0200
Source: pypdf
Architecture: source
Version: 6.19.0-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Python Team <team+python@tracker.debian.org>
Changed-By: Pieter Lenaerts <plenae@disroot.org>
Closes: 1134731 1134733 1134736 1134737 1134738 1138192 1138193 1138194 1140629 1141339 1141771 1143902 1146476 1146638
Changes:
 pypdf (6.19.0-1) unstable; urgency=medium
 .
   * New version 6.19.0
     (Closes: 1134731, 1134733, 1134736, 1134737, 1134738, 1138192, 1138193,
     1138194, 1140629, 1141339, 1141771, 1143902, 1146476, 1146638)
   * Refresh patches
   * debian/patches/0001-Use-formal-Cryptodome-namespace.patch: add unpad to import
   * d/control:
     - New build deps for tests
     - Bump debhelper-compat to 14, remove obsolete substvars
     - Switch python3-flit to flit build-dep
     - Enable dh-sequence-single-binary
     - Add suggests for some dependencies
   * d/copyright, d/patches/0004-replace-old-unicode-license.patch, debian/source/lintian-overrides:
     fix lintian tag license-problem-old-unicode
Checksums-Sha1:
 f7993119857d87820da0a0c986713ff04b3f5e6b 2365 pypdf_6.19.0-1.dsc
 bb11e87bcf8bc040f49eafa2928e06c6ee7507d3 8459308 pypdf_6.19.0.orig.tar.xz
 fde600cd380fd4a09e02c22bd9ef47af048b17f2 13136 pypdf_6.19.0-1.debian.tar.xz
 e14620cc2d007e3497db3291fa2a2338d291d60d 9795 pypdf_6.19.0-1_source.buildinfo
Checksums-Sha256:
 4b82faf852bbff61dfdaf4c5b2af689c9de55e3626a8b8a7b21d40e53f39ff23 2365 pypdf_6.19.0-1.dsc
 f4b8092a6c99c3864415ada7f5e0b895b3eff865b6b6398e0053b31fc0827e19 8459308 pypdf_6.19.0.orig.tar.xz
 e3f37ae43b4484a99f8e746d8860d53d178d8ba09957f3a67d61aa9a73c40efa 13136 pypdf_6.19.0-1.debian.tar.xz
 9a9a5355164c5d4f9f66c25a992e48178f1272425c20a66d969da28c9103516b 9795 pypdf_6.19.0-1_source.buildinfo
Files:
 e7c6259773a683a0107636e704cbfc57 2365 python optional pypdf_6.19.0-1.dsc
 4a1a8b24694efc42f8182d67453bb828 8459308 python optional pypdf_6.19.0.orig.tar.xz
 cac1b8b1526d6d22cc678c28482c98ab 13136 python optional pypdf_6.19.0-1.debian.tar.xz
 319c778fcde7cd1de2ca56cf4cf5a134 9795 python optional pypdf_6.19.0-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEj23hBDd/OxHnQXSHMfMURUShdBoFAmq8+gkACgkQMfMURUSh
dBobGw//STjUQHUWSfdjEePAk+sUFw/Eeu0BmhB1iP9eveMmad5TRp8xEYXTviNZ
PB76+deIPqtK0fXb62YukT9uRvf7UTcoMKJ5PUtz+UIWr/n5BuSb6bFJefy0Krjc
F56j4dnhUW3M/49PbFLRNqoir9nnXYSSCEEowWdFpBqsm6eBWgsLyQ1cwVoCF/x0
xpBrqMNJTO/82bHrkYjNmCqXIsR0Uco0tE+DmDUxqpBU4q7yKgYn3KHiVGWNcexB
oI+2Lzs8r7l03DNsrhkKDhdnuNE//kzikLc551x0J8yeY/HYfxK2iqlFzVmWPJ5k
lWKJywnx4DInWQMASnyJx+aOKSLQ7jzv4MJ7/RwUsNdkMz4CXe/Me/N/d0vsXibb
bkSaXpXadLcSnJdfVVKau9rqqeyAfpCmDgWKrTXl7+RsoPmXAnejHVQbcA+IBUpn
8H5pFWR372PBfmI6M1XxQIZ9AoMS8HS3P6GogJ0Cs3gCFB0YUmJAAtioNW9f3RfI
fFxBDRAyABFfymBwZD6CjZ/iS+nR8uoMYWIFcA5LGHakHPjeElMTxEbAsnHsfjdV
w4G6lUBIr+38VYWvH2j6mJdBhds1kBUPginLKHwbpeSbGklqTD4+Hmn4iPxFJ7Lh
IbJjZvQNHiRbRjAJggpUe85945VZJDdHWbrO2Dasc3sC2iJeYGM=
=m1GQ
-----END PGP SIGNATURE-----