Feed/CVE-2026-71870
CVE-2026-71870MEDIUMCVSS 0.0

pypdf: Possible large memory usage for large /ToUnicode streams

Published Aug 7, 2026·Updated Aug 9, 2026

NVD Description

### Impact An attacker who uses this vulnerability can craft a PDF which leads to large memory consumption. This requires parsing the `/ToUnicode` entry of a font with unusually large values, for example during text extraction. ### Patches This has been fixed in [pypdf==6.15.0](https://github.com/py-pdf/pypdf/releases/tag/6.15.0). ### Workarounds If you cannot upgrade yet, consider applying the changes from PR [#3944](https://github.com/py-pdf/pypdf/pull/3944).

Affected Packages (1)

pypdfPYPI
Fixed in 6.15.0

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free