PT-2026-103584 · Pypi · Pypdf

·

CVE-2026-102993

·

Published

2026-09-30

·

Updated

2026-10-02

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions pypdf versions prior to 6.17.0
Description A crafted PDF file can contain unusually large Roman page-label values. When an application retrieves document page labels, the pypdf/ page labels.py module generates excessively large numeral strings, leading to high memory consumption and potentially causing the application to become unavailable.
Recommendations Update to version 6.17.0.

Exploit

Fix

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102993
GHSA-QV6H-RV94-W285
PYSEC-2026-4158

Affected Products

Pypdf