Description
pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an application retrieves document page labels, consuming large amounts of memory and potentially making the application unavailable. This issue is fixed in version 6.17.0.
Published: 2026-09-30
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via excessive memory consumption
Action: Patch Immediately
AI Analysis

Impact

A malformed PDF that includes unusually large Roman page‑label values can cause the pypdf library to generate enormous numeral strings. When an application queries a PDF’s page labels, this logic can consume a large portion or all of available memory, potentially crashing or stalling the process that loaded the document. The weakness is rooted in a lack of size validation for the labels (CWE‑400) and the unbounded memory allocation (CWE‑770). Compromise of confidentiality, integrity, or availability is limited to the affected process, as the flaw does not allow code execution, but the impact on availability can be severe if the application continues to process untrusted PDFs.

Affected Systems

py‑pdf pypdf library, specifically all releases prior to version 6.17.0. Any software that imports or uses pypdf to read PDF documents and subsequently accesses page labels is at risk. Vendors using older pypdf versions in production systems should verify the library version and consider upgrades.

Risk and Exploitability

The CVSS score of 8.7 classifies this flaw as High severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local or remote file inclusion: an adversary can supply a crafted PDF to an application that processes PDFs with pypdf. Because the flaw causes a memory exhaustion event, it is a denial‑of‑service condition. An attacker does not need elevated privileges or to exploit a network service; simply providing the malicious PDF to any process using pypdf is sufficient. The potential impact is limited to the process’s availability, but if the application is critical, the broader system may be affected.

Generated by OpenCVE AI on September 30, 2026 at 23:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the pypdf library to version 6.17.0 or later, which contains the fix for large Roman page label handling.
  • Restrict or disable page label retrieval for untrusted PDFs to prevent high memory usage when using older pypdf versions.
  • Validate or enforce a maximum Roman label size before invoking page label logic, or run PDF processing in a sandboxed environment to limit memory usage.

Generated by OpenCVE AI on September 30, 2026 at 23:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-qv6h-rv94-w285 pypdf: Possible large memory usage when retrieving Roman page labels
History

Fri, 02 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Pypdf Project
Pypdf Project pypdf
CPEs cpe:2.3:a:pypdf_project:pypdf:*:*:*:*:*:*:*:*
Vendors & Products Pypdf Project
Pypdf Project pypdf
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Thu, 01 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Py-pdf
Py-pdf pypdf
Vendors & Products Py-pdf
Py-pdf pypdf

Thu, 01 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Wed, 30 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an application retrieves document page labels, consuming large amounts of memory and potentially making the application unavailable. This issue is fixed in version 6.17.0.
Title pypdf: Possible large memory usage when retrieving Roman page labels
Weaknesses CWE-400
CWE-770
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-02T16:32:16.809Z

Reserved: 2026-09-29T20:46:08.334Z

Link: CVE-2026-102993

cve-icon Vulnrichment

Updated: 2026-10-02T16:32:12.691Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-30T20:17:27.630

Modified: 2026-10-02T17:17:01.203

Link: CVE-2026-102993

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-30T19:55:52Z

Links: CVE-2026-102993 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T06:15:14Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-770

    Allocation of Resources Without Limits or Throttling