Threat Advisory

pypdf Flaw Triggers Large Memory Consumption

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting pypdf versions < 6.16.1 affecting pypdf versions < 6.15.0 affecting pypdf versions < 6.16.0.

CVE-2026-71870 (CVSS 4.8 — Severity): An attacker who uses this vulnerability can craft a PDF which leads to large memory consumption by parsing the `/ToUnicode` entry of a font with unusually large values.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting pypdf versions < 6.16.1 affecting pypdf versions < 6.15.0 affecting pypdf versions < 6.16.0.

CVE-2026-71870 (CVSS 4.8 — Severity): An attacker who uses this vulnerability can craft a PDF which leads to large memory consumption by parsing the `/ToUnicode` entry of a font with unusually large values.[emaillocker id="1283"]

CVE-2026-84309 (CVSS 6.9 — Severity): An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop by requiring a (usually writing) code path where `TreeObject.insert_child` is involved.

CVE-2026-84311 (CVSS 4.8 — Severity): An attacker who uses this vulnerability can craft a PDF which leads to long runtimes and large memory consumption by extracting the text of a page with lots of XForm objects, where some of them might be re-used.

CVE-2026-84310 (CVSS 4.8 — Severity): An attacker who uses this vulnerability can craft a PDF which leads to long runtimes and large memory consumption by accessing the outlines of a document with either lots of entries or nested outlines with long re-used nesting paths.

These vulnerabilities collectively present significant risks for administrators, particularly those handling sensitive data.

RECOMMENDATION:

We recommend you to update pypdf to version 6.15.0 or 6.16.0 or 6.16.1 depending on your installed branch.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu