OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-102996

HIGH · CVSS 7.5 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The pypdf library prior to version 6.18.1 is vulnerable to a memory consumption issue triggered by specially crafted PDFs containing oversized /Widths arrays for TrueType or Type1 fonts. This vulnerability can lead to excessive memory usage during operations like text extraction, potentially resulting in denial-of-service conditions. Developers and organizations utilizing pypdf for PDF processing should prioritize upgrading to version 6.18.1 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102996
Severity
HIGH
CVSS
7.5
EPSS
0.30%

Original NVD Description

pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can provide a TrueType or Type1 simple font with an unusually large /Widths array, causing pypdf/_font.py Font._collect_tt_t1_character_widths to process entries beyond the 256 character codes meaningful for a simple font and consume excessive memory during operations such as text extraction. This issue is fixed in version 6.18.1.

Related CVEs

Other vulnerabilities affecting the same vendor(s)