<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T05:16:27.793224+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-07657</id>
    <title>bdu:2023-07657</title>
    <updated>2026-10-09T05:16:27.799171+00:00</updated>
    <content>bdu:2023-07657</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-07657"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-205648</id>
    <title>EUVD-2026-205648</title>
    <updated>2026-10-09T05:16:27.799226+00:00</updated>
    <content>EUVD-2026-205648</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-205648"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-36464</id>
    <title>fkie_cve-2023-36464</title>
    <updated>2026-10-09T05:16:27.799242+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>pypdf is an open source, pure-python PDF library. In affected versions an attacker may craft a PDF which leads to an infinite loop if `__parse_content_stream` is executed. That is, for example, the case if the user extracted text from such a PDF. This issue was introduced in pull request #969 and resolved in pull request #1828. Users are advised to upgrade. Users unable to upgrade may modify the line `while peek not in (b"\r", b"\n")` in `pypdf/generic/_data_structures.py` to `while peek not in (b"\r", b"\n", b"")`.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-36464"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4vvm-4w3v-6mr8</id>
    <title>GHSA-4vvm-4w3v-6mr8 — pypdf and PyPDF2 possible Infinite Loop when a comment isn't followed by a character</title>
    <updated>2026-10-09T05:16:27.799278+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: pypdf, PyPI: PyPDF2</p>
<p>### Impact
An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop if `__parse_content_stream` is executed. This infinite loop blocks the current process and can utilize a single core of the CPU by 100%. It does not affect memory usage. That is, for example, the case if the user extracted text from such a PDF.</p>
<p>Example Code and a PDF that causes the issue:</p>
<p>```python
from pypdf import PdfReader</p>
<p># https://objects.githubusercontent.com/github-production-repository-file-5c1aeb/3119517/11367871?X-Amz-Algorithm=AWS4-HMAC-SHA256&amp;X-Amz-Credential=AKIAIWNJYAX4CSVEH53A%2F20230627%2Fus-east-1%2Fs3%2Faws4_request&amp;X-Amz-Date=20230627T201018Z&amp;X-Amz-Expires=300&amp;X-Amz-Signature=d71c8fd9181c4875f0c04d563b6d32f1d4da6e7b2e6be2f14479ce4ecdc9c8b2&amp;X-Amz-SignedHeaders=host&amp;actor_id=1658117&amp;key_id=0&amp;repo_id=3119517&amp;response-content-disposition=attachment%3Bfilename%3DMiFO_LFO_FEIS_NOA_Published.3.pdf&amp;response-content-type=application%2Fpdf
reader = PdfReader("MiFO_LFO_FEIS_NOA_Published.3.pdf")
page = reader.pages[0]
page.extract_text()
```</p>
<p>The issue was introduced with https://github.com/py-pdf/pypdf/pull/969</p>
<p>### Patches</p>
<p>The issue was fixed with https://github.com/py-pdf/pypdf/pull/1828</p>
<p>### Workarounds</p>
<p>It is recommended to upgrade to `pypdf&gt;=3.9.0`. PyPDF2 users should migrate to pypdf.</p>
<p>If you cannot update your version of pypdf, you should modify `pypdf/generic/_data_structures.py`:</p>
<p>```
OLD: while peek not in (b"\r", b"\n"):
NEW: while peek not in (b"\r",…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4vvm-4w3v-6mr8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-36464</id>
    <title>gsd-2023-36464</title>
    <updated>2026-10-09T05:16:27.799328+00:00</updated>
    <content>gsd-2023-36464</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-36464"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-1835</id>
    <title>PYSEC-2026-1835 — pypdf and PyPDF2 possible Infinite Loop when a comment isn't followed by a character</title>
    <updated>2026-10-09T05:16:27.799341+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: pypdf2</p>
<p>### Impact
An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop if `__parse_content_stream` is executed. This infinite loop blocks the current process and can utilize a single core of the CPU by 100%. It does not affect memory usage. That is, for example, the case if the user extracted text from such a PDF.</p>
<p>Example Code and a PDF that causes the issue:</p>
<p>```python
from pypdf import PdfReader</p>
<p># https://objects.githubusercontent.com/github-production-repository-file-5c1aeb/3119517/11367871?X-Amz-Algorithm=AWS4-HMAC-SHA256&amp;X-Amz-Credential=AKIAIWNJYAX4CSVEH53A%2F20230627%2Fus-east-1%2Fs3%2Faws4_request&amp;X-Amz-Date=20230627T201018Z&amp;X-Amz-Expires=300&amp;X-Amz-Signature=d71c8fd9181c4875f0c04d563b6d32f1d4da6e7b2e6be2f14479ce4ecdc9c8b2&amp;X-Amz-SignedHeaders=host&amp;actor_id=1658117&amp;key_id=0&amp;repo_id=3119517&amp;response-content-disposition=attachment%3Bfilename%3DMiFO_LFO_FEIS_NOA_Published.3.pdf&amp;response-content-type=application%2Fpdf
reader = PdfReader("MiFO_LFO_FEIS_NOA_Published.3.pdf")
page = reader.pages[0]
page.extract_text()
```</p>
<p>The issue was introduced with https://github.com/py-pdf/pypdf/pull/969</p>
<p>### Patches</p>
<p>The issue was fixed with https://github.com/py-pdf/pypdf/pull/1828</p>
<p>### Workarounds</p>
<p>It is recommended to upgrade to `pypdf&gt;=3.9.0`. PyPDF2 users should migrate to pypdf.</p>
<p>If you cannot update your version of pypdf, you should modify `pypdf/generic/_data_structures.py`:</p>
<p>```
OLD: while peek not in (b"\r", b"\n"):
NEW: while peek not in (b"\r",…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-1835"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2023:4974</id>
    <title>RHBA-2023:4974 — Red Hat Bug Fix Advisory: Red Hat Quay v3.9.1 minor release</title>
    <updated>2026-10-09T05:16:27.799380+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>pypdf: Possible Infinite Loop when a comment isn't followed by a character</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2023:4974"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-36464</id>
    <title>UBUNTU-CVE-2023-36464</title>
    <updated>2026-10-09T05:16:27.799398+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: pypdf, Ubuntu:25.10: pypdf, Ubuntu:26.04:LTS: pypdf</p>
<p>pypdf is an open source, pure-python PDF library. In affected versions an attacker may craft a PDF which leads to an infinite loop if `__parse_content_stream` is executed. That is, for example, the case if the user extracted text from such a PDF. This issue was introduced in pull request #969 and resolved in pull request #1828. Users are advised to upgrade. Users unable to upgrade may modify the line `while peek not in (b"\r", b"\n")` in `pypdf/generic/_data_structures.py` to `while peek not in (b"\r", b"\n", b"")`.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-36464"/>
  </entry>
</feed>
