Impact
pypdf, a pure‑Python PDF library, has a flaw that allows an attacker to supply a PDF containing an unusually large /Widths array in a TrueType or Type 1 simple font. When the library parses such a PDF, the Font._collect_tt_t1_character_widths routine processes entries beyond the 256 meaningful character codes, resulting in excessive memory usage during operations such as text extraction. The impact is a denial‑of‑service through memory exhaustion, which can affect any process that incorporates pypdf to parse untrusted PDFs. The weakness is classified as CWE‑400.
Affected Systems
The vulnerability exists in the py‑pdf pypdf package for all releases older than version 6.18.1. Systems or applications that depend on pypdf 6.18.0 or earlier, especially those exposed to external PDFs, are at risk. Upgrading to 6.18.1 or later remedies the issue.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability. The EPSS score is not available, but the lack of a publicly listed KEV and the nature of the flaw suggest that exploitation relies on delivering a malicious PDF to a vulnerable application. The likely attack vector is remote or local, depending on whether the application interfaces with external PDF input. An attacker who can drive the PDF processing path can trigger a denial‑of‑service by exhausting memory resources, and the vulnerability could be exploited by any party able to control the PDF content.
OpenCVE Enrichment