EXECUTIVE SUMMARY:
Multiple security vulnerabilities affecting pypdf have been identified in pypdf, a Python package used to read and write PDF files. The overall risk/impact is significant, as an attacker can craft a malicious PDF that leads to large memory consumption or long runtimes.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Multiple security vulnerabilities affecting pypdf have been identified in pypdf, a Python package used to read and write PDF files. The overall risk/impact is significant, as an attacker can craft a malicious PDF that leads to large memory consumption or long runtimes.[emaillocker id="1283"]
CVE-2026-102993 (CVSS 8.7 — High): An attacker who uses this vulnerability can craft a PDF which leads to large memory consumption by accessing the page labels of a document with large Roman numerals.
CVE-2026-102994 (CVSS 8.7 — High): An attacker who uses this vulnerability can craft a PDF which leads to long runtimes by reading a PDF document with long indirect object headers, not terminated by whitespace.
CVE-2026-102995 (CVSS 8.7 — High): An attacker who uses this vulnerability can craft a PDF which leads to large memory consumption by parsing the /ToUnicode entry of a font with unusually large values, for example during text extraction.
CVE-2026-102996 (CVSS 8.7 — High): An attacker who uses this vulnerability can craft a PDF which leads to large memory consumption by parsing the /Widths entry of a TrueType or Type1 fonts with unusually large values, for example during text extraction.
CVE-2026-102997 (CVSS 8.7 — High): An attacker who uses this vulnerability can craft a PDF which leads to long runtimes for partially malformed FlateDecode streams by reading a PDF document with long indirect object headers, not terminated by whitespace.
CVE-2026-103000 (CVSS 8.7 — High): It allows an attacker to craft a malicious PDF with large alphabetical page labels that cause excessive memory consumption when the page labels are accessed.
CVE-2026-102998 (CVSS 8.7 — High): It allows an attacker to craft a malicious PDF that causes long runtimes when form field values are updated with flattening enabled triggering appearance stream generation.
CVE-2026-102999 (CVSS 8.7 — High): It allows an attacker to craft a malicious PDF that causes long runtimes when embedded files are accessed through the dictionary-based API.
RECOMMENDATIONS:
REFERENCES:
The following reports contain further technical details:
https://github.com/advisories/GHSA-qv6h-rv94-w285
https://github.com/advisories/GHSA-5jq2-8x83-x246
https://github.com/advisories/GHSA-fp3h-c4fm-7vvf
https://github.com/advisories/GHSA-g9cg-prrw-2r8q
https://github.com/advisories/GHSA-jw7q-gvrg-4vj3
https://github.com/advisories/GHSA-w23x-9jrw-r45c
https://github.com/advisories/GHSA-php9-fj8v-98fj
https://github.com/advisories/GHSA-v247-6f48-mgcj