Memory Consumption Vulnerability in pypdf PDF Library by PyPDF
CVE-2026-102995

8.7HIGH

Key Information:

Vendor

Py-PDF

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-102995?

The pypdf library, an open-source Python tool for handling PDF files, has a vulnerability that affects versions earlier than 6.18.1. When processing specifically crafted PDF files containing unusually large source-code or destination-string tokens in font mappings, the library can incur excessive memory usage during operations such as text extraction. This issue stems from a parsing flaw within the _cmap.py module, where oversized values can be decoded and retained, leading to potential denial of service due to memory exhaustion. The issue has been addressed in version 6.18.1, which mitigates this risk.

Affected Version(s)

pypdf < 6.18.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.