Excessive Memory Consumption in pypdf PDF Library
CVE-2026-71852
4.8MEDIUM
What is CVE-2026-71852?
The pypdf library, a free and open-source pure-Python PDF tool, is vulnerable to significant performance issues due to improper handling of certain PDF font data during text extraction. Specifically, prior to version 6.15.0, crafted PDFs could trigger long processing times and excessive memory use when handling expanded CID font width ranges or an unusually high number of width entries. This flaw highlights the importance of using the latest library versions to ensure optimal performance and secure document processing.
Affected Version(s)
pypdf < 6.15.0
