PT-2026-69116 · Pypi · Pypdf

CVE-2026-71852

·

Published

2026-08-07

·

Updated

2026-08-10

CVSS v4.0

4.8

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions pypdf versions prior to 6.15.0
Description A crafted PDF can cause long runtimes and large memory consumption during text extraction. This occurs when the Font. collect cid character widths() function in pypdf/ font.py expands unusually large CID font /W width ranges or excessive width entries. CID (Character Identifier) fonts are a way of mapping characters to glyphs in PDF files.
Recommendations Update to version 6.15.0. As a temporary workaround, apply the changes from PR #3946.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71852
ECHO-D342-478D-0776
GHSA-FWG2-594C-JP42
PYSEC-2026-3656

Affected Products

Pypdf