CVE-2026-102993

high

Description

pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an application retrieves document page labels, consuming large amounts of memory and potentially making the application unavailable. This issue is fixed in version 6.17.0.

References

https://github.com/py-pdf/pypdf/security/advisories/GHSA-qv6h-rv94-w285

https://github.com/py-pdf/pypdf/releases/tag/6.17.0

https://github.com/py-pdf/pypdf/pull/4047

https://github.com/py-pdf/pypdf/commit/89db7c4fe9315ecc964bfdf05a4e8c4b94175163

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-90365

Details

Source: Mitre, NVD

Published: 2026-09-30

Updated: 2026-10-02

Named Vulnerability: GHSA-qv6h-rv94-w285

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity: High

CVSS v4

Base Score: 8.7

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Severity: High

EPSS

EPSS: 0.00524