{"id":"CVE-2026-71852","aliases":["GHSA-fwg2-594c-jp42","PYSEC-2026-3656"],"url":"https://o3.security/vulnerability/CVE-2026-71852","summary":"pypdf: Possible long runtimes/large memory usage for large CID font width ranges","details":"### Impact\n\nAn attacker who uses this vulnerability can craft a PDF which leads to long runtimes and large memory consumption. This requires parsing the font width entries of a font with unusually large values, for example during text extraction.\n\n### Patches\n\nThis has been fixed in [pypdf==6.15.0](https://github.com/py-pdf/pypdf/releases/tag/6.15.0).\n\n### Workarounds\n\nIf you cannot upgrade yet, consider applying the changes from PR [#3946](https://github.com/py-pdf/pypdf/pull/3946).","published":"2026-08-07T18:53:46.083Z","modified":"2026-09-12T03:46:52.397895523Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"pypdf","fixedVersion":"6.15.0"}],"fix":{"url":"https://github.com/py-pdf/pypdf/commit/51cb6acf9e8a35b77e90b4d87d28fe3e1416d7d7","label":"py-pdf/pypdf@51cb6ac"},"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.15.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71852.json"},{"type":"ADVISORY","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-fwg2-594c-jp42"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71852"},{"type":"FIX","url":"https://github.com/py-pdf/pypdf/commit/51cb6acf9e8a35b77e90b4d87d28fe3e1416d7d7"},{"type":"FIX","url":"https://github.com/py-pdf/pypdf/pull/3946"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-12T03:46:52.397895523Z"}}