Description
pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can place unusually large source-code or destination-string tokens in a font /ToUnicode mapping, causing pypdf/_cmap.py parse_bfchar to decode and retain oversized values during operations such as text extraction and consume excessive memory. This is a second follow-up to earlier /ToUnicode resource-consumption fixes and is limited to the remaining token-length path. This issue is fixed in version 6.18.1.
Published: 2026-09-30
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Large memory consumption leading to possible denial of service
Action: Update
AI Analysis

Impact

pypdf processes PDF files that contain a /ToUnicode dictionary with an unusually long source‑code or destination‑string token. The parse_bfchar routine decodes and retains these oversized tokens, allocating memory proportionate to the token length. An attacker can craft a PDF to trigger this path, causing the interpreter to consume excessive memory during text extraction and potentially crash or become unresponsive. This is an unbounded memory consumption flaw (CWE‑400).

Affected Systems

The flaw exists in the py‑pdf:pypdf library in all releases before version 6.18.1. Any application importing pypdf that can receive arbitrary PDFs is at risk. Versions 6.18.1 and later are not affected.

Risk and Exploitability

The CVSS score of 8.7 classifies the issue as high severity. While EPSS data is unavailable, the low technical barriers to supply a malicious PDF suggest that exploitation is reasonably feasible, especially in environments where PDF parsing is performed automatically. The vulnerability is not listed in the CISA KEV catalog, but the lack of a published exploit does not reduce the theoretical importance. The likely attack vector is the delivery of a crafted PDF through email, a web page, or any interface that triggers pypdf to parse the file, leading to denial of service via memory exhaustion.

Generated by OpenCVE AI on September 30, 2026 at 22:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the pypdf library to version 6.18.1 or later, which removes the overflow path for oversized /ToUnicode tokens.
  • Validate or limit the size of PDF input before invoking pypdf to prevent extremely large token extraction.
  • Execute PDF parsing inside a sandboxed or memory‑restricted process to contain potential memory overconsumption.

Generated by OpenCVE AI on September 30, 2026 at 22:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can place unusually large source-code or destination-string tokens in a font /ToUnicode mapping, causing pypdf/_cmap.py parse_bfchar to decode and retain oversized values during operations such as text extraction and consume excessive memory. This is a second follow-up to earlier /ToUnicode resource-consumption fixes and is limited to the remaining token-length path. This issue is fixed in version 6.18.1.
Title pypdf: Possible large memory usage for large /ToUnicode streams (Follow-up 2)
Weaknesses CWE-400
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-30T20:01:43.354Z

Reserved: 2026-09-29T20:46:08.334Z

Link: CVE-2026-102995

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T21:17:06.713

Modified: 2026-09-30T21:17:06.713

Link: CVE-2026-102995

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-30T20:01:43Z

Links: CVE-2026-102995 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T22:45:16Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-770

    Allocation of Resources Without Limits or Throttling