Disclosure summary
pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can provide a TrueType or Type1 simple font with an unusually large /Widths array, causing pypdf/_font.py Font._collect_tt_t1_character_widths to process entries beyond the 256 character codes meaningful for a simple font and consume excessive memory during operations such as text extraction. This issue is fixed in version 6.18.1.
Source-reported weakness categories
CWE-400
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-102996
Open original source · Updated Oct 05, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| pypdf_project | pypdf | * {"versionEndExcluding":"6.18.1"} |
GitHub Reviewed Security Advisories · GHSA-g9cg-prrw-2r8q
Open original source · Updated Oct 01, 2026
pypdf: Possible large memory usage when parsing font data
Source severity: HIGH / 8.7
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | pypdf | < 6.18.1 | 6.18.1 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Patch
- github.com — Patch, Issue Tracking
- github.com — Release Notes
- github.com — Vendor Advisory
PUBLISHED 2026-09-30T17:17:06-04:00
MODIFIED 2026-10-05T11:13:17-04:00
INGESTED 2026-10-06T11:44:59-04:00