Multiple security vulnerabilities affecting pypdf versions < 6.16.1 affecting pypdf versions < 6.15.0 affecting pypdf versions < 6.16.0.
CVE-2026-71870 (CVSS 4.8 — Severity): An attacker who uses this vulnerability can craft a PDF which leads to large memory consumption by parsing the `/ToUnicode` entry of a font with unusually large values.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting pypdf versions < 6.16.1 affecting pypdf versions < 6.15.0 affecting pypdf versions < 6.16.0.
CVE-2026-71870 (CVSS 4.8 — Severity): An attacker who uses this vulnerability can craft a PDF which leads to large memory consumption by parsing the `/ToUnicode` entry of a font with unusually large values.[emaillocker id="1283"]
CVE-2026-84309 (CVSS 6.9 — Severity): An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop by requiring a (usually writing) code path where `TreeObject.insert_child` is involved.
CVE-2026-84311 (CVSS 4.8 — Severity): An attacker who uses this vulnerability can craft a PDF which leads to long runtimes and large memory consumption by extracting the text of a page with lots of XForm objects, where some of them might be re-used.
CVE-2026-84310 (CVSS 4.8 — Severity): An attacker who uses this vulnerability can craft a PDF which leads to long runtimes and large memory consumption by accessing the outlines of a document with either lots of entries or nested outlines with long re-used nesting paths.
These vulnerabilities collectively present significant risks for administrators, particularly those handling sensitive data.
We recommend you to update pypdf to version 6.15.0 or 6.16.0 or 6.16.1 depending on your installed branch.
The following reports contain further technical details:
[/emaillocker]