Impact
A malformed PDF that includes unusually large Roman page‑label values can cause the pypdf library to generate enormous numeral strings. When an application queries a PDF’s page labels, this logic can consume a large portion or all of available memory, potentially crashing or stalling the process that loaded the document. The weakness is rooted in a lack of size validation for the labels (CWE‑400) and the unbounded memory allocation (CWE‑770). Compromise of confidentiality, integrity, or availability is limited to the affected process, as the flaw does not allow code execution, but the impact on availability can be severe if the application continues to process untrusted PDFs.
Affected Systems
py‑pdf pypdf library, specifically all releases prior to version 6.17.0. Any software that imports or uses pypdf to read PDF documents and subsequently accesses page labels is at risk. Vendors using older pypdf versions in production systems should verify the library version and consider upgrades.
Risk and Exploitability
The CVSS score of 8.7 classifies this flaw as High severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local or remote file inclusion: an adversary can supply a crafted PDF to an application that processes PDFs with pypdf. Because the flaw causes a memory exhaustion event, it is a denial‑of‑service condition. An attacker does not need elevated privileges or to exploit a network service; simply providing the malicious PDF to any process using pypdf is sufficient. The potential impact is limited to the process’s availability, but if the application is critical, the broader system may be affected.
OpenCVE Enrichment
Github GHSA