Memory Exhaustion Vulnerability in pypdf Library by PyPDF
CVE-2026-103000

8.7HIGH

Key Information:

Vendor

Py-PDF

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-103000?

The pypdf library, a widely used Python library for PDF manipulation, was found to have a vulnerability that could lead to memory exhaustion. Prior to version 6.19.0, a crafted PDF document could contain excessively large alphabetical page-label values. When applications processing these documents retrieve the page labels, it may result in the generation of strings that far exceed reasonable lengths. This situation can lead to excessive memory consumption, potentially causing applications to become unavailable. Users are encouraged to upgrade to version 6.19.0 where this issue has been effectively addressed.

Affected Version(s)

pypdf < 6.19.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.