<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 17:31:02 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-07661</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-07661</link>
      <description>bdu:2023-07661</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-07661</guid>
    </item>
    <item>
      <title>EUVD-2026-199799</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-199799</link>
      <description>EUVD-2026-199799</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-199799</guid>
    </item>
    <item>
      <title>fkie_cve-2023-36807</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-36807</link>
      <description>&lt;p&gt;pypdf is a pure-python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files. In version 2.10.5 an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This infinite loop blocks the current process and can utilize a single core of the CPU by 100%. It does not affect memory usage. That is, for example, the case if the user extracted metadata from such a malformed PDF. Versions prior to 2.10.5 throw an error, but do not hang forever. This issue was fixed with https://github.com/py-pdf/pypdf/pull/1331 which has been included in release 2.10.6. Users are advised to upgrade. Users unable to upgrade should modify `PyPDF2/generic/_data_structures.py::read_object` to an an error throwing case. See GHSA-hm9v-vj3r-r55m for details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;pypdf is a pure-python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files. In version 2.10.5 an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This infinite loop blocks the current process and can utilize a single core of the CPU by 100%. It does not affect memory usage. That is, for example, the case if the user extracted metadata from such a malformed PDF. Versions prior to 2.10.5 throw an error, but do not hang forever. This issue was fixed with https://github.com/py-pdf/pypdf/pull/1331 which has been included in release 2.10.6. Users are advised to upgrade. Users unable to upgrade should modify `PyPDF2/generic/_data_structures.py::read_object` to an an error throwing case. See GHSA-hm9v-vj3r-r55m for details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-36807</guid>
    </item>
    <item>
      <title>GHSA-hm9v-vj3r-r55m — PyPDF2 vulnerable to possible Infinite Loop when reading malformed objects</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hm9v-vj3r-r55m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: PyPDF2&lt;/p&gt;
&lt;p&gt;### Impact
An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop.
This infinite loop blocks the current process and can utilize a single core of the CPU by 100%. It does not affect memory usage. That is, for example, the case if the user extracted metadata from such a malformed PDF.&lt;/p&gt;
&lt;p&gt;### Patches
The issue was fixed with https://github.com/py-pdf/pypdf/pull/1331&lt;/p&gt;
&lt;p&gt;### Workarounds
If you cannot update your version of `PyPDF2` (preferably to `pypdf&amp;gt;3.1.0` as PyPDF2 is deprecated), you should modify `PyPDF2/generic/_data_structures.py::read_object`.&lt;/p&gt;
&lt;p&gt;Replace:&lt;/p&gt;
&lt;p&gt;```python
    else:
        # number object OR indirect reference
        peek = stream.read(20)
        stream.seek(-len(peek), 1)  # reset to start
        if IndirectPattern.match(peek) is not None:
            return IndirectObject.read_from_stream(stream, pdf)
        else:
            return NumberObject.read_from_stream(stream)
```&lt;/p&gt;
&lt;p&gt;by&lt;/p&gt;
&lt;p&gt;```python
    elif tok in b&amp;#34;0123456789+-.&amp;#34;:
        # number object OR indirect reference
        peek = stream.read(20)
        stream.seek(-len(peek), 1)  # reset to start
        if IndirectPattern.match(peek) is not None:
            return IndirectObject.read_from_stream(stream, pdf)
        else:
            return NumberObject.read_from_stream(stream)
    else:
        raise PdfReadError(
            f&amp;#34;Invalid Elementary Object starting with {tok} @{stream.tell()}&amp;#34;
        )
```&lt;/p&gt;
&lt;p&gt;### References
* [pypdf issue #1329](https://github.com/py-pdf/py…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: PyPDF2&lt;/p&gt;
&lt;p&gt;### Impact
An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop.
This infinite loop blocks the current process and can utilize a single core of the CPU by 100%. It does not affect memory usage. That is, for example, the case if the user extracted metadata from such a malformed PDF.&lt;/p&gt;
&lt;p&gt;### Patches
The issue was fixed with https://github.com/py-pdf/pypdf/pull/1331&lt;/p&gt;
&lt;p&gt;### Workarounds
If you cannot update your version of `PyPDF2` (preferably to `pypdf&amp;gt;3.1.0` as PyPDF2 is deprecated), you should modify `PyPDF2/generic/_data_structures.py::read_object`.&lt;/p&gt;
&lt;p&gt;Replace:&lt;/p&gt;
&lt;p&gt;```python
    else:
        # number object OR indirect reference
        peek = stream.read(20)
        stream.seek(-len(peek), 1)  # reset to start
        if IndirectPattern.match(peek) is not None:
            return IndirectObject.read_from_stream(stream, pdf)
        else:
            return NumberObject.read_from_stream(stream)
```&lt;/p&gt;
&lt;p&gt;by&lt;/p&gt;
&lt;p&gt;```python
    elif tok in b&amp;#34;0123456789+-.&amp;#34;:
        # number object OR indirect reference
        peek = stream.read(20)
        stream.seek(-len(peek), 1)  # reset to start
        if IndirectPattern.match(peek) is not None:
            return IndirectObject.read_from_stream(stream, pdf)
        else:
            return NumberObject.read_from_stream(stream)
    else:
        raise PdfReadError(
            f&amp;#34;Invalid Elementary Object starting with {tok} @{stream.tell()}&amp;#34;
        )
```&lt;/p&gt;
&lt;p&gt;### References
* [pypdf issue #1329](https://github.com/py-pdf/py…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hm9v-vj3r-r55m</guid>
    </item>
    <item>
      <title>gsd-2023-36807</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-36807</link>
      <description>gsd-2023-36807</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-36807</guid>
    </item>
    <item>
      <title>PYSEC-2026-1836 — PyPDF2 vulnerable to possible Infinite Loop when reading malformed objects</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-1836</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pypdf2&lt;/p&gt;
&lt;p&gt;### Impact
An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop.
This infinite loop blocks the current process and can utilize a single core of the CPU by 100%. It does not affect memory usage. That is, for example, the case if the user extracted metadata from such a malformed PDF.&lt;/p&gt;
&lt;p&gt;### Patches
The issue was fixed with https://github.com/py-pdf/pypdf/pull/1331&lt;/p&gt;
&lt;p&gt;### Workarounds
If you cannot update your version of `PyPDF2` (preferably to `pypdf&amp;gt;3.1.0` as PyPDF2 is deprecated), you should modify `PyPDF2/generic/_data_structures.py::read_object`.&lt;/p&gt;
&lt;p&gt;Replace:&lt;/p&gt;
&lt;p&gt;```python
    else:
        # number object OR indirect reference
        peek = stream.read(20)
        stream.seek(-len(peek), 1)  # reset to start
        if IndirectPattern.match(peek) is not None:
            return IndirectObject.read_from_stream(stream, pdf)
        else:
            return NumberObject.read_from_stream(stream)
```&lt;/p&gt;
&lt;p&gt;by&lt;/p&gt;
&lt;p&gt;```python
    elif tok in b&amp;#34;0123456789+-.&amp;#34;:
        # number object OR indirect reference
        peek = stream.read(20)
        stream.seek(-len(peek), 1)  # reset to start
        if IndirectPattern.match(peek) is not None:
            return IndirectObject.read_from_stream(stream, pdf)
        else:
            return NumberObject.read_from_stream(stream)
    else:
        raise PdfReadError(
            f&amp;#34;Invalid Elementary Object starting with {tok} @{stream.tell()}&amp;#34;
        )
```&lt;/p&gt;
&lt;p&gt;### References
* [pypdf issue #1329](https://github.com/py-pdf/py…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pypdf2&lt;/p&gt;
&lt;p&gt;### Impact
An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop.
This infinite loop blocks the current process and can utilize a single core of the CPU by 100%. It does not affect memory usage. That is, for example, the case if the user extracted metadata from such a malformed PDF.&lt;/p&gt;
&lt;p&gt;### Patches
The issue was fixed with https://github.com/py-pdf/pypdf/pull/1331&lt;/p&gt;
&lt;p&gt;### Workarounds
If you cannot update your version of `PyPDF2` (preferably to `pypdf&amp;gt;3.1.0` as PyPDF2 is deprecated), you should modify `PyPDF2/generic/_data_structures.py::read_object`.&lt;/p&gt;
&lt;p&gt;Replace:&lt;/p&gt;
&lt;p&gt;```python
    else:
        # number object OR indirect reference
        peek = stream.read(20)
        stream.seek(-len(peek), 1)  # reset to start
        if IndirectPattern.match(peek) is not None:
            return IndirectObject.read_from_stream(stream, pdf)
        else:
            return NumberObject.read_from_stream(stream)
```&lt;/p&gt;
&lt;p&gt;by&lt;/p&gt;
&lt;p&gt;```python
    elif tok in b&amp;#34;0123456789+-.&amp;#34;:
        # number object OR indirect reference
        peek = stream.read(20)
        stream.seek(-len(peek), 1)  # reset to start
        if IndirectPattern.match(peek) is not None:
            return IndirectObject.read_from_stream(stream, pdf)
        else:
            return NumberObject.read_from_stream(stream)
    else:
        raise PdfReadError(
            f&amp;#34;Invalid Elementary Object starting with {tok} @{stream.tell()}&amp;#34;
        )
```&lt;/p&gt;
&lt;p&gt;### References
* [pypdf issue #1329](https://github.com/py-pdf/py…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-1836</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2023-36807</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-36807</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: pypdf2, Ubuntu:Pro:16.04:LTS: pypdf2, Ubuntu:18.04:LTS: pypdf2, Ubuntu:Pro:18.04:LTS: pypdf2, Ubuntu:20.04:LTS: pypdf2, Ubuntu:22.04:LTS: pypdf2&lt;/p&gt;
&lt;p&gt;pypdf is a pure-python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files. In version 2.10.5 an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This infinite loop blocks the current process and can utilize a single core of the CPU by 100%. It does not affect memory usage. That is, for example, the case if the user extracted metadata from such a malformed PDF. Versions prior to 2.10.5 throw an error, but do not hang forever. This issue was fixed with https://github.com/py-pdf/pypdf/pull/1331 which has been included in release 2.10.6. Users are advised to upgrade. Users unable to upgrade should modify `PyPDF2/generic/_data_structures.py::read_object` to an an error throwing case. See GHSA-hm9v-vj3r-r55m for details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: pypdf2, Ubuntu:Pro:16.04:LTS: pypdf2, Ubuntu:18.04:LTS: pypdf2, Ubuntu:Pro:18.04:LTS: pypdf2, Ubuntu:20.04:LTS: pypdf2, Ubuntu:22.04:LTS: pypdf2&lt;/p&gt;
&lt;p&gt;pypdf is a pure-python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files. In version 2.10.5 an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This infinite loop blocks the current process and can utilize a single core of the CPU by 100%. It does not affect memory usage. That is, for example, the case if the user extracted metadata from such a malformed PDF. Versions prior to 2.10.5 throw an error, but do not hang forever. This issue was fixed with https://github.com/py-pdf/pypdf/pull/1331 which has been included in release 2.10.6. Users are advised to upgrade. Users unable to upgrade should modify `PyPDF2/generic/_data_structures.py::read_object` to an an error throwing case. See GHSA-hm9v-vj3r-r55m for details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-36807</guid>
    </item>
  </channel>
</rss>
