CVE-2026-22690: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-22690 is a denial-of-service vulnerability in pypdf, a free and open-source pure-Python PDF library, caused by uncontrolled resource consumption (CWE-400) when processing malformed PDF files in non-strict reading mode. An attacker can craft an invalid PDF that omits the /Root entry in the trailer while specifying a large /Size value, causing pypdf to iterate through every object number up to the /Size limit, resulting in excessively long processing runtimes. All versions of pypdf prior to 6.6.0 are affected; the vulnerability was disclosed on January 9, 2026, and patched the same day. It carries a CVSS v3.1 base score of 5.3 (Medium) and a CVSS v4.0 base score of 2.7 (Low) (Github Advisory, pypdf Security Advisory).

Technical details

The root cause is insufficient bounds checking during PDF root object recovery in non-strict mode (CWE-400: Uncontrolled Resource Consumption). When pypdf's PdfReader cannot locate a /Root entry in the PDF trailer, it falls back to scanning all objects up to the number specified by the trailer's /Size field. An attacker can set /Size to an arbitrarily large integer while omitting /Root, forcing pypdf to attempt to retrieve and inspect each object in sequence — a potentially enormous loop. The fix introduced a root_object_recovery_limit parameter (defaulting to 10,000) on PdfReader, which raises a LimitReachedError if the scan exceeds this threshold; the patch also replaced a regex-based xref rebuild with a string.find()-based approach and added cyclic page reference detection (pypdf Security Advisory, Patch PR #3594, Commit 2941657).

Impact

Successful exploitation causes a denial-of-service condition by consuming excessive CPU and processing time on the host running pypdf in non-strict mode. Applications that accept and process user-supplied PDF files — such as document management systems, web services, or automated pipelines — are most at risk, as a single malformed PDF can render the processing service unresponsive or severely degrade throughput. There is no impact on confidentiality or integrity; only availability is affected, and the scope is limited to the vulnerable system (Github Advisory, pypdf Security Advisory).

Exploitability

No public proof-of-concept exploit code is known, and there is no evidence of in-the-wild exploitation at this time (Github Advisory). The vulnerability requires no authentication, no privileges, and no user interaction — an attacker only needs to supply a crafted PDF to an application using pypdf in non-strict mode. The EPSS score is approximately 0.042% (very low probability of exploitation within 30 days), and the CVE is not listed in the CISA Known Exploited Vulnerabilities catalog (Github Advisory).

Exploitation steps

  1. Craft a malicious PDF: Create a minimal PDF file that omits the /Root entry from the trailer dictionary but sets /Size to a very large integer (e.g., several million), making the file structurally invalid but parseable in non-strict mode.
  2. Deliver the PDF: Submit the crafted PDF to any application or service that processes PDFs using pypdf in its default (non-strict) mode — for example, via a file upload endpoint, email attachment processor, or document conversion API.
  3. Trigger resource exhaustion: When pypdf's PdfReader attempts to open the file, it fails to find /Root and enters its recovery loop, iterating through object numbers from 1 up to the large /Size value. Each iteration attempts to fetch and inspect an object, consuming CPU cycles for the duration.
  4. Achieve denial of service: The processing thread or worker is occupied for an extended period, potentially causing timeouts, service unavailability, or cascading failures if multiple such PDFs are submitted concurrently (pypdf Security Advisory, Patch PR #3594).

Indicators of compromise

  • Logs: Application logs showing pypdf PdfReader warnings such as 'Searching object with "/Catalog" key' or 'Invalid Root object in trailer' for files submitted by external users; repeated occurrences may indicate probing.
  • Process/Performance: Sustained high CPU usage by Python worker processes handling PDF parsing, particularly for files that are small on disk but cause long processing times.
  • File System: Presence of PDF files with unusually large /Size values in the trailer but minimal or no actual object content; these files may be very small in size relative to their declared object count.
  • Network: Repeated uploads or submissions of PDF files from the same source IP that consistently trigger long processing times or timeouts in PDF handling services.

Mitigation and workarounds

Upgrade pypdf to version 6.6.0 or later, which introduces a root_object_recovery_limit (defaulting to 10,000 objects) that prevents unbounded iteration during root object recovery (pypdf Release 6.6.0). If immediate upgrade is not possible, switch to strict reading mode as a workaround: use PdfReader("file.pdf", strict=True) instead of the default non-strict mode, or PdfWriter(clone_from=PdfReader("file.pdf", strict=True)) for write operations (pypdf Security Advisory). Additionally, implement input validation to reject PDFs from untrusted sources before processing, and consider rate-limiting or sandboxing PDF processing workloads to contain the impact of any exploitation attempt.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

pypdf2

Affected

sid

pypdf: 6.9.0-1

Fixed

trixie

pypdf

Affected

Ubuntu

Unknown

bionic (esm-apps)

pypdf2

Unknown

devel

pypdf

Unknown

focal (esm-apps)

pypdf2

Unknown

jammy

pypdf2

Unknown

jammy (esm-apps)

pypdf2

Unknown

noble

pypdf

Unknown

noble (esm-apps)

pypdf

Unknown

resolute

pypdf

Unknown

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management