CVE-2026-103000
Received Received - Intake

Memory Exhaustion via Large PDF Page Labels in pypdf

Vulnerability report for CVE-2026-103000, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: GitHub, Inc.

Description

pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF can provide unusually large alphabetical page-label values that cause pypdf/_page_labels.py to generate strings beyond a reasonable page-label length when an application retrieves document page labels, consuming excessive memory and potentially making the application unavailable. This issue is fixed in version 6.19.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
py-pdf pypdf 6.19.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the pypdf library, a pure-python PDF library. A crafted PDF file can provide excessively large page-label values, causing the library to generate abnormally long strings when retrieving document page labels. This leads to excessive memory consumption and potential denial of service by making the application unavailable.

Detection Guidance

This vulnerability can be detected by checking the version of pypdf installed on your system. Run 'pip show pypdf' or 'pip list | grep pypdf' to verify if the version is below 6.19.0. If it is, the system is vulnerable.

Impact Analysis

If you use the pypdf library in your application, an attacker could exploit this vulnerability by providing a malicious PDF file. This could cause your application to consume too much memory, slow down, or crash entirely, disrupting normal operations.

Compliance Impact

The vulnerability in pypdf could potentially impact compliance with GDPR or HIPAA by causing denial-of-service conditions due to excessive memory consumption, which may disrupt availability of systems handling sensitive data. However, the specific compliance impact depends on how the library is used in a given environment.

Mitigation Strategies

Immediately update pypdf to version 6.19.0 or later using 'pip install --upgrade pypdf'. If upgrading is not possible, consider removing or restricting access to applications using pypdf until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103000. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart