Description
pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can provide a TrueType or Type1 simple font with an unusually large /Widths array, causing pypdf/_font.py Font._collect_tt_t1_character_widths to process entries beyond the 256 character codes meaningful for a simple font and consume excessive memory during operations such as text extraction. This issue is fixed in version 6.18.1.
Published: 2026-09-30
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Denial-of-Service via memory exhaustion
Action: Patch Immediately
AI Analysis

Impact

pypdf, a pure‑Python PDF library, has a flaw that allows an attacker to supply a PDF containing an unusually large /Widths array in a TrueType or Type 1 simple font. When the library parses such a PDF, the Font._collect_tt_t1_character_widths routine processes entries beyond the 256 meaningful character codes, resulting in excessive memory usage during operations such as text extraction. The impact is a denial‑of‑service through memory exhaustion, which can affect any process that incorporates pypdf to parse untrusted PDFs. The weakness is classified as CWE‑400.

Affected Systems

The vulnerability exists in the py‑pdf pypdf package for all releases older than version 6.18.1. Systems or applications that depend on pypdf 6.18.0 or earlier, especially those exposed to external PDFs, are at risk. Upgrading to 6.18.1 or later remedies the issue.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity vulnerability. The EPSS score is not available, but the lack of a publicly listed KEV and the nature of the flaw suggest that exploitation relies on delivering a malicious PDF to a vulnerable application. The likely attack vector is remote or local, depending on whether the application interfaces with external PDF input. An attacker who can drive the PDF processing path can trigger a denial‑of‑service by exhausting memory resources, and the vulnerability could be exploited by any party able to control the PDF content.

Generated by OpenCVE AI on September 30, 2026 at 22:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the py‑pdf pypdf package to version 6.18.1 or later.
  • If an upgrade is not immediately possible, validate incoming PDF files for an excessively large /Widths array before handing them to the library, or skip processing of fonts that exceed 256 width entries.
  • Isolate PDF parsing in a resource‑restricted environment such as a sandbox, and consider implementing memory limits or timeouts for text extraction operations.

Generated by OpenCVE AI on September 30, 2026 at 22:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Wed, 30 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can provide a TrueType or Type1 simple font with an unusually large /Widths array, causing pypdf/_font.py Font._collect_tt_t1_character_widths to process entries beyond the 256 character codes meaningful for a simple font and consume excessive memory during operations such as text extraction. This issue is fixed in version 6.18.1.
Title pypdf: Possible large memory usage when parsing font data
Weaknesses CWE-400
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-30T20:48:39.148Z

Reserved: 2026-09-29T20:46:08.335Z

Link: CVE-2026-102996

cve-icon Vulnrichment

Updated: 2026-09-30T20:48:35.319Z

cve-icon NVD

Status : Received

Published: 2026-09-30T21:17:06.863

Modified: 2026-09-30T21:17:06.863

Link: CVE-2026-102996

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-30T20:03:55Z

Links: CVE-2026-102996 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T23:00:17Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-770

    Allocation of Resources Without Limits or Throttling