CVE-2026-102995High· 8.7▾ Twilightpypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can place unusually large source-code or destination-string tokens in a font /ToUnicode mapping, causing pypdf/_cmap.py parse_bfchar to decode and re…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can place unusually large source-code or destination-string tokens in a font /ToUnicode mapping, causing pypdf/_cmap.py parse_bfchar to decode and retain oversized values during operations such as text extraction and consume excessive memory. This is a second follow-up to earlier /ToUnicode resource-consumption fixes and is limited to the remaining token-length path. This issue is fixed in version 6.18.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102996High· 8.7pypdf is a free and open-source pure-python PDF library
CVE-2026-102997High· 8.7pypdf is a free and open-source pure-python PDF library
CVE-2026-102999High· 8.7pypdf is a free and open-source pure-python PDF library
CVE-2026-103000High· 8.7pypdf is a free and open-source pure-python PDF library
CVE-2026-102998High· 8.7pypdf is a free and open-source pure-python PDF library
CVE-2026-102993High· 8.7pypdf is a free and open-source pure-python PDF library