{"id":"CVE-2026-102996","aliases":["GHSA-g9cg-prrw-2r8q","PYSEC-2026-4155"],"url":"https://o3.security/vulnerability/CVE-2026-102996","summary":"pypdf: Possible large memory usage when parsing font data","details":"pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can provide a TrueType or Type1 simple font with an unusually large /Widths array, causing pypdf/_font.py Font._collect_tt_t1_character_widths to process entries beyond the 256 character codes meaningful for a simple font and consume excessive memory during operations such as text extraction. This issue is fixed in version 6.18.1.","published":"2026-09-30T20:03:55.880Z","modified":"2026-10-02T03:47:25.973889160Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"pypdf","fixedVersion":"6.18.1"}],"fix":{"url":"https://github.com/py-pdf/pypdf/commit/0fb26eb8cdd01c44b3b2c9fe8329751be2f7cfd5","label":"py-pdf/pypdf@0fb26eb"},"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.18.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102996.json"},{"type":"ADVISORY","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-g9cg-prrw-2r8q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102996"},{"type":"FIX","url":"https://github.com/py-pdf/pypdf/commit/0fb26eb8cdd01c44b3b2c9fe8329751be2f7cfd5"},{"type":"FIX","url":"https://github.com/py-pdf/pypdf/pull/4072"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-10-02T03:47:25.973889160Z"}}