CVE-2026-48155

EUVD-2026-32914
pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires extracting text in layout mode with large character offsets. This vulnerability is fixed in 6.12.0.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 2.6%
Affected Products (NVD)
VendorProductVersion
pypdf_projectpypdf
𝑥
< 6.12.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pypdf
bookworm
no-dsa
forky
vulnerable
sid
vulnerable
trixie
no-dsa
pypdf2
bookworm
no-dsa
bullseye
postponed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pypdf
jammy
dne
noble
needs-triage
questing
ignored
resolute
needs-triage
pypdf2
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
dne
resolute
dne
xenial
needs-triage