Memory Consumption Vulnerability in pypdf PDF Library by PyPDF
CVE-2026-102995
8.7HIGH
What is CVE-2026-102995?
The pypdf library, an open-source Python tool for handling PDF files, has a vulnerability that affects versions earlier than 6.18.1. When processing specifically crafted PDF files containing unusually large source-code or destination-string tokens in font mappings, the library can incur excessive memory usage during operations such as text extraction. This issue stems from a parsing flaw within the _cmap.py module, where oversized values can be decoded and retained, leading to potential denial of service due to memory exhaustion. The issue has been addressed in version 6.18.1, which mitigates this risk.
Affected Version(s)
pypdf < 6.18.1
