MEDIUM 4.8 NVD
CVE-2026-71870
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumption when pypdf/_cmap.py function parse_bf
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumption when pypdf/_cmap.py function parse_bfrange parses unusually large source-code or destination-string tokens in a font /ToUnicode CMap during text extraction. This issue is fixed in 6.15.0.
References
- https://github.com/py-pdf/pypdf/commit/afba8080e19d29a3c256a742b340995e695b35aa
- https://github.com/py-pdf/pypdf/pull/3944
- https://github.com/py-pdf/pypdf/releases/tag/6.15.0
- https://github.com/py-pdf/pypdf/security/advisories/GHSA-fp3f-mc75-235c
This medium severity vulnerability with a CVSS score of 4.8 was published on 2026-08-07 via NVD.
vulnfeed aggregates 8893 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.