Excessive Memory Consumption in pypdf PDF Library
CVE-2026-71852

4.8MEDIUM

Key Information:

Vendor

Py-PDF

Status
Vendor
CVE Published:
7 August 2026

What is CVE-2026-71852?

The pypdf library, a free and open-source pure-Python PDF tool, is vulnerable to significant performance issues due to improper handling of certain PDF font data during text extraction. Specifically, prior to version 6.15.0, crafted PDFs could trigger long processing times and excessive memory use when handling expanded CID font width ranges or an unusually high number of width entries. This flaw highlights the importance of using the latest library versions to ensure optimal performance and secure document processing.

Affected Version(s)

pypdf < 6.15.0

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.