GHSA-g9cg-prrw-2r8qHigh
pypdf: Possible large memory usage when parsing font data
🔗 CVE IDs covered (1)
📋 Description
Impact
An attacker who uses this vulnerability can craft a PDF which leads to large memory consumption. This requires parsing the /Widths entry of a TrueType or Type1 fonts with unusually large values, for example during text extraction.
Patches
This has been fixed in pypdf==6.18.1.
Workarounds
If you cannot upgrade yet, consider applying the changes from PR #4072.
🎯 Affected products1
- pip/pypdf:< 6.18.1
🔗 References (6)
- https://github.com/py-pdf/pypdf/security/advisories/GHSA-g9cg-prrw-2r8q
- https://nvd.nist.gov/vuln/detail/CVE-2026-102996
- https://github.com/py-pdf/pypdf/pull/4072
- https://github.com/py-pdf/pypdf/commit/0fb26eb8cdd01c44b3b2c9fe8329751be2f7cfd5
- https://github.com/py-pdf/pypdf/releases/tag/6.18.1
- https://github.com/advisories/GHSA-g9cg-prrw-2r8q