Memory Consumption Issue in pypdf PDF Library by PyPDF
CVE-2026-102996
8.7HIGH
What is CVE-2026-102996?
The pypdf library, a widely used open-source PDF processing tool, experiences a vulnerability that allows crafted PDF files to define a TrueType or Type1 font with an oversized /Widths array. This anomaly causes the Font._collect_tt_t1_character_widths function to handle more character width entries than the expected limit of 256, leading to excessive memory usage during operations like text extraction. Users should update to version 6.18.1 to mitigate this issue.
Affected Version(s)
pypdf < 6.18.1
