CyberRota Analysis
AI-GeneratedThe pypdf library prior to version 6.18.1 is vulnerable to a memory consumption issue triggered by specially crafted PDFs containing oversized /Widths arrays for TrueType or Type1 fonts. This vulnerability can lead to excessive memory usage during operations like text extraction, potentially resulting in denial-of-service conditions. Developers and organizations utilizing pypdf for PDF processing should prioritize upgrading to version 6.18.1 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can provide a TrueType or Type1 simple font with an unusually large /Widths array, causing pypdf/_font.py Font._collect_tt_t1_character_widths to process entries beyond the 256 character codes meaningful for a simple font and consume excessive memory during operations such as text extraction. This issue is fixed in version 6.18.1.
Related CVEs
Other vulnerabilities affecting the same vendor(s)