PT-2026-20908 · Pypi+1 · Pypdf+1

Cheonwoong-Park

·

Published

2026-02-18

·

Updated

2026-06-04

·

CVE-2026-27025

CVSS v4.0

6.9

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions pypdf versions prior to 6.7.1
Description pypdf is a free and open-source pure-python PDF library. An attacker can create a malicious PDF file that causes excessive runtime and memory usage when processed. This occurs when parsing the /ToUnicode entry of a font containing unusually large values, such as during text extraction.
Recommendations Update to version 6.7.1 or later.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07223
CVE-2026-27025
GHSA-WGVP-VG3V-2XQ3
OPENSUSE-SU-2026:10238-1
OPENSUSE-SU-2026:20333-1

Affected Products

Red Os
Pypdf