PT-2026-103591 · Pypi · Pypdf

CVE-2026-103000

·

Published

2026-09-30

·

Updated

2026-10-01

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions pypdf versions prior to 6.19.0
Description A crafted PDF file can contain unusually large alphabetical page-label values. When an application retrieves document page labels, the pypdf/ page labels.py module generates strings that exceed a reasonable length, leading to excessive memory consumption and potentially causing the application to become unavailable.
Recommendations Update to version 6.19.0.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103000

Affected Products

Pypdf