Memory Consumption Issue in pypdf Library by PyPDF
CVE-2026-48735

6.9MEDIUM

Key Information:

Vendor

Py-PDF

Status
Vendor
CVE Published:
28 May 2026

What is CVE-2026-48735?

The pypdf library, a free and open-source pure-Python PDF processing tool, contains a vulnerability that allows an attacker to craft specific PDF files leading to excessive memory usage. This issue arises from the handling of large XMP metadata elements, which may contain unnecessary information, resulting in resource exhaustion. This vulnerability has been addressed in version 6.12.1, where the memory handling during PDF parsing has been improved.

Affected Version(s)

pypdf < 6.12.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.