
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22690 is a denial-of-service vulnerability in pypdf, a free and open-source pure-Python PDF library, caused by uncontrolled resource consumption (CWE-400) when processing malformed PDF files in non-strict reading mode. An attacker can craft an invalid PDF that omits the /Root entry in the trailer while specifying a large /Size value, causing pypdf to iterate through every object number up to the /Size limit, resulting in excessively long processing runtimes. All versions of pypdf prior to 6.6.0 are affected; the vulnerability was disclosed on January 9, 2026, and patched the same day. It carries a CVSS v3.1 base score of 5.3 (Medium) and a CVSS v4.0 base score of 2.7 (Low) (Github Advisory, pypdf Security Advisory).
The root cause is insufficient bounds checking during PDF root object recovery in non-strict mode (CWE-400: Uncontrolled Resource Consumption). When pypdf's PdfReader cannot locate a /Root entry in the PDF trailer, it falls back to scanning all objects up to the number specified by the trailer's /Size field. An attacker can set /Size to an arbitrarily large integer while omitting /Root, forcing pypdf to attempt to retrieve and inspect each object in sequence — a potentially enormous loop. The fix introduced a root_object_recovery_limit parameter (defaulting to 10,000) on PdfReader, which raises a LimitReachedError if the scan exceeds this threshold; the patch also replaced a regex-based xref rebuild with a string.find()-based approach and added cyclic page reference detection (pypdf Security Advisory, Patch PR #3594, Commit 2941657).
Successful exploitation causes a denial-of-service condition by consuming excessive CPU and processing time on the host running pypdf in non-strict mode. Applications that accept and process user-supplied PDF files — such as document management systems, web services, or automated pipelines — are most at risk, as a single malformed PDF can render the processing service unresponsive or severely degrade throughput. There is no impact on confidentiality or integrity; only availability is affected, and the scope is limited to the vulnerable system (Github Advisory, pypdf Security Advisory).
No public proof-of-concept exploit code is known, and there is no evidence of in-the-wild exploitation at this time (Github Advisory). The vulnerability requires no authentication, no privileges, and no user interaction — an attacker only needs to supply a crafted PDF to an application using pypdf in non-strict mode. The EPSS score is approximately 0.042% (very low probability of exploitation within 30 days), and the CVE is not listed in the CISA Known Exploited Vulnerabilities catalog (Github Advisory).
/Root entry from the trailer dictionary but sets /Size to a very large integer (e.g., several million), making the file structurally invalid but parseable in non-strict mode.PdfReader attempts to open the file, it fails to find /Root and enters its recovery loop, iterating through object numbers from 1 up to the large /Size value. Each iteration attempts to fetch and inspect an object, consuming CPU cycles for the duration.PdfReader warnings such as 'Searching object with "/Catalog" key' or 'Invalid Root object in trailer' for files submitted by external users; repeated occurrences may indicate probing./Size values in the trailer but minimal or no actual object content; these files may be very small in size relative to their declared object count.Upgrade pypdf to version 6.6.0 or later, which introduces a root_object_recovery_limit (defaulting to 10,000 objects) that prevents unbounded iteration during root object recovery (pypdf Release 6.6.0). If immediate upgrade is not possible, switch to strict reading mode as a workaround: use PdfReader("file.pdf", strict=True) instead of the default non-strict mode, or PdfWriter(clone_from=PdfReader("file.pdf", strict=True)) for write operations (pypdf Security Advisory). Additionally, implement input validation to reject PDFs from untrusted sources before processing, and consider rate-limiting or sandboxing PDF processing workloads to contain the impact of any exploitation attempt.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."