Impact
The vulnerability arises when pypdf processes PDFs containing unusually large alphabetical page labels. The library attempts to create page‑label strings that exceed a practical size, forcing excessive memory allocation. An application that calls the page‑label retrieval routine can be overwhelmed, leading to memory exhaustion or failure, which is effectively a denial of service. The flaw is an instance of uncontrolled memory allocation, classified as CWE‑400.
Affected Systems
The issue affects the Python library pypdf (py‑pdf:pypdf) in all versions released before 6.19.0. The fix is included in the 6.19.0 release. Users of older versions that parse PDF documents in ways that trigger page‑label processing are exposed.
Risk and Exploitability
With a CVSS score of 8.7 the severity is high. No EPSS score is available, and the vulnerability is not listed in CISA KEV. Exploitation requires delivery of a crafted PDF to a vulnerable application that uses pypdf to retrieve page labels. The threat vector is therefore indirect, mediated by the application’s PDF processing, and the attacker needs the ability to supply the malicious file. If successful, the attack can consume significant memory, potentially causing the target to become unresponsive.
OpenCVE Enrichment