CVE-2026-40260
EUVD-2026-2332717.04.2026, 01:17
pypdf is a free and open-source pure-python PDF library. In versions prior to 6.10.0, manipulated XMP metadata entity declarations can exhaust RAM. An attacker who exploits this vulnerability can craft a PDF which leads to large memory usage. This requires parsing the XMP metadata. This issue has been fixed in version 6.10.0.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| pypdf_project | pypdf | 𝑥 < 6.10.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases