Summary
pypdf: Possible long runtimes/large memory usage when extracting XForm objects
Advisory details
Impact
An attacker who uses this vulnerability can craft a PDF which leads to long runtimes and large memory consumption. This requires extracting the text of a page with lots of XForm objects, where some of them might be re-used.
Patches
This has been fixed in pypdf==6.16.1.
Workarounds
If you cannot upgrade yet, consider applying the changes from PR #3966.
References
Related vulnerabilities
All Supply chain →- MEDIUMCVE-2026-84310
pypdf: Possible long runtimes/large memory usage when retrieving outlines
- MEDIUMCVE-2026-71852
pypdf: Possible long runtimes/large memory usage for large CID font width ranges
- HIGHCVE-2026-64641
Next.js: Denial of Service in App Router using Server Actions
- HIGHGHSA-7q9c-hpx7-9cwm
TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop
- CRITICALCVE-2026-73842
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation
- MEDIUMCVE-2026-73557
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts