Memory Consumption Issue in pypdf PDF Library by PyPDF
CVE-2026-102993
8.7HIGH
What is CVE-2026-102993?
The pypdf library, a widely used open-source Python library for handling PDF files, has a vulnerability that can lead to excessive memory consumption when processing specially crafted PDF files. Prior to version 6.17.0, these malicious PDFs can include unusually large Roman page-label values, causing the library's component _page_labels.py to generate extremely large numeral strings. This results in significant memory usage, potentially rendering applications that depend on pypdf unavailable. Users are encouraged to upgrade to version 6.17.0 or later to mitigate this issue.
Affected Version(s)
pypdf < 6.17.0
