Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-102995— pypdf: Possible large memory usage for large /ToUnicode streams (Follow-up 2)

Quick assessment

Affected
py-pdf pypdf
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

pypdf 是一个免费且开源的纯 Python PDF 处理库。在 6.18.1 版本之前,经过恶意构造的 PDF 文件可以在字体的 /ToUnicode 映射中放置异常大的源代码(source-code)或目标字符串(destination-string)令牌,导致 pypdf/_cmap.py 中的 parse_bfchar 函数在文本提取等操作过程中解码并保留这些超大值,从而消耗过量内存。该问题是此前针对 /ToUnicode 资源消耗漏洞修复工作的第二次后续跟进,仅涉及剩余的令牌长度处理路径。此问题已在 6

CVSS 8.7 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-102995

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
pypdf: Possible large memory usage for large /ToUnicode streams (Follow-up 2)
Source: CVE Program / CVE List V5
Vulnerability Description
pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can place unusually large source-code or destination-string tokens in a font /ToUnicode mapping, causing pypdf/_cmap.py parse_bfchar to decode and retain oversized values during operations such as text extraction and consume excessive memory. This is a second follow-up to earlier /ToUnicode resource-consumption fixes and is limited to the remaining token-length path. This issue is fixed in version 6.18.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
py-pdf pypdf < 6.18.1 -

II. Public POCs for CVE-2026-102995

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-102995

请登录查看更多情报信息。

Other References for CVE-2026-102995 (4)

Same Patch Batch · py-pdf · 2026-09-30 · 8 CVEs total

CVE-2026-102998 8.7 HIGH pypdf: Possible long runtimes when generating appearance streams
CVE-2026-102997 8.7 HIGH pypdf: Possible long runtimes for partially malformed FlateDecode streams (Follow-up)
CVE-2026-102993 8.7 HIGH pypdf: Possible large memory usage when retrieving Roman page labels
CVE-2026-102994 8.7 HIGH pypdf: Possible long runtimes/large memory usage when parsing indirect objects
CVE-2026-102996 8.7 HIGH pypdf: Possible large memory usage when parsing font data
CVE-2026-102999 8.7 HIGH pypdf: Possible long runtimes with large amount of embedded files
CVE-2026-103000 8.7 HIGH pypdf: Possible large memory usage when retrieving alphabetical page labels

IV. Related Vulnerabilities

V. Comments for CVE-2026-102995

No comments yet


Leave a comment