pypdf 是一个免费且开源的纯 Python PDF 处理库。在 6.18.1 版本之前,经过恶意构造的 PDF 文件可以在字体的 /ToUnicode 映射中放置异常大的源代码(source-code)或目标字符串(destination-string)令牌,导致 pypdf/_cmap.py 中的 parse_bfchar 函数在文本提取等操作过程中解码并保留这些超大值,从而消耗过量内存。该问题是此前针对 /ToUnicode 资源消耗漏洞修复工作的第二次后续跟进,仅涉及剩余的令牌长度处理路径。此问题已在 6
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102998 | 8.7 HIGH | pypdf: Possible long runtimes when generating appearance streams |
| CVE-2026-102997 | 8.7 HIGH | pypdf: Possible long runtimes for partially malformed FlateDecode streams (Follow-up) |
| CVE-2026-102993 | 8.7 HIGH | pypdf: Possible large memory usage when retrieving Roman page labels |
| CVE-2026-102994 | 8.7 HIGH | pypdf: Possible long runtimes/large memory usage when parsing indirect objects |
| CVE-2026-102996 | 8.7 HIGH | pypdf: Possible large memory usage when parsing font data |
| CVE-2026-102999 | 8.7 HIGH | pypdf: Possible long runtimes with large amount of embedded files |
| CVE-2026-103000 | 8.7 HIGH | pypdf: Possible large memory usage when retrieving alphabetical page labels |
No comments yet