Summary
pypdf: Possible long runtimes/large memory usage for large CID font width ranges
Advisory details
Impact
An attacker who uses this vulnerability can craft a PDF which leads to long runtimes and large memory consumption. This requires parsing the font width entries of a font with unusually large values, for example during text extraction.
Patches
This has been fixed in pypdf==6.15.0.
Workarounds
If you cannot upgrade yet, consider applying the changes from PR #3946.
References
Related vulnerabilities
All Supply chain →- MEDIUMCVE-2026-84310
pypdf: Possible long runtimes/large memory usage when retrieving outlines
- MEDIUMCVE-2026-84311
pypdf: Possible long runtimes/large memory usage when extracting XForm objects
- HIGHCVE-2026-64641
Next.js: Denial of Service in App Router using Server Actions
- HIGHGHSA-7q9c-hpx7-9cwm
TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop
- CRITICALCVE-2026-73842
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation
- MEDIUMCVE-2026-73557
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts