Memory Consumption Issue in pypdf PDF Library by PyPDF
CVE-2026-102996

8.7HIGH

Key Information:

Vendor

Py-PDF

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-102996?

The pypdf library, a widely used open-source PDF processing tool, experiences a vulnerability that allows crafted PDF files to define a TrueType or Type1 font with an oversized /Widths array. This anomaly causes the Font._collect_tt_t1_character_widths function to handle more character width entries than the expected limit of 256, leading to excessive memory usage during operations like text extraction. Users should update to version 6.18.1 to mitigate this issue.

Affected Version(s)

pypdf < 6.18.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.