Description
pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF can provide unusually large alphabetical page-label values that cause pypdf/_page_labels.py to generate strings beyond a reasonable page-label length when an application retrieves document page labels, consuming excessive memory and potentially making the application unavailable. This issue is fixed in version 6.19.0.
Published: 2026-09-30
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The vulnerability arises when pypdf processes PDFs containing unusually large alphabetical page labels. The library attempts to create page‑label strings that exceed a practical size, forcing excessive memory allocation. An application that calls the page‑label retrieval routine can be overwhelmed, leading to memory exhaustion or failure, which is effectively a denial of service. The flaw is an instance of uncontrolled memory allocation, classified as CWE‑400.

Affected Systems

The issue affects the Python library pypdf (py‑pdf:pypdf) in all versions released before 6.19.0. The fix is included in the 6.19.0 release. Users of older versions that parse PDF documents in ways that trigger page‑label processing are exposed.

Risk and Exploitability

With a CVSS score of 8.7 the severity is high. No EPSS score is available, and the vulnerability is not listed in CISA KEV. Exploitation requires delivery of a crafted PDF to a vulnerable application that uses pypdf to retrieve page labels. The threat vector is therefore indirect, mediated by the application’s PDF processing, and the attacker needs the ability to supply the malicious file. If successful, the attack can consume significant memory, potentially causing the target to become unresponsive.

Generated by OpenCVE AI on September 30, 2026 at 22:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the pypdf library to version 6.19.0 or later.
  • If upgrade is not immediately possible, modify the application to restrict or disable access to page‑label information, or to enforce a maximum label length.
  • Continuously monitor memory consumption of PDF‑parsing processes and apply throttling or restart mechanisms when anomalous usage is detected.

Generated by OpenCVE AI on September 30, 2026 at 22:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Wed, 30 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF can provide unusually large alphabetical page-label values that cause pypdf/_page_labels.py to generate strings beyond a reasonable page-label length when an application retrieves document page labels, consuming excessive memory and potentially making the application unavailable. This issue is fixed in version 6.19.0.
Title pypdf: Possible large memory usage when retrieving alphabetical page labels
Weaknesses CWE-400
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-30T20:49:21.058Z

Reserved: 2026-09-29T20:46:08.335Z

Link: CVE-2026-103000

cve-icon Vulnrichment

Updated: 2026-09-30T20:49:17.959Z

cve-icon NVD

Status : Received

Published: 2026-09-30T21:17:07.490

Modified: 2026-09-30T21:17:07.490

Link: CVE-2026-103000

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-30T20:13:00Z

Links: CVE-2026-103000 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T22:30:07Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-770

    Allocation of Resources Without Limits or Throttling