Bug 2544277 (CVE-2026-102996)

Summary: CVE-2026-102996 pypdf: pypdf: Denial of Service via excessive memory consumption during font parsing
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: anpicker, bbrownin, blitton, bparees, doconnor, dschmidt, ebourniv, hasun, ikhan, jfula, jlanda, jowilson, kshier, mbarnett, nyancey, ometelka, ptisnovs, rbobbitt, sbunciak, simaishi, stcannon, syedriko, xdharmai, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in pypdf. This vulnerability allows an attacker to cause a Denial of Service (DoS) by providing a specially crafted PDF document with an oversized font character width array. When processing the document during operations such as text extraction, the library allocates excessive memory, leading to resource exhaustion and potential application failure.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-30 20:32:11 UTC
pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can provide a TrueType or Type1 simple font with an unusually large /Widths array, causing pypdf/_font.py Font._collect_tt_t1_character_widths to process entries beyond the 256 character codes meaningful for a simple font and consume excessive memory during operations such as text extraction. This issue is fixed in version 6.18.1.