Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-71870

Опубликовано: 07 авг. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumption when pypdf/_cmap.py function parse_bfrange parses unusually large source-code or destination-string tokens in a font /ToUnicode CMap during text extraction. This issue is fixed in 6.15.0.

A flaw was found in pypdf, a pure-python PDF library. A remote attacker could exploit this vulnerability by providing a specially crafted PDF file. When the library attempts to parse unusually large font /ToUnicode CMap streams during text extraction, it can lead to excessive memory consumption. This can result in a denial of service (DoS) for applications processing such malicious PDF files.

Отчет

A flaw in the pypdf library can lead to a denial of service due to uncontrolled resource consumption. Processing a specially crafted PDF file containing unusually large /ToUnicode streams can cause excessive memory allocation, impacting the availability of Red Hat products that rely on pypdf for PDF processing. This issue requires user interaction to trigger the vulnerable parsing.

Меры по смягчению последствий

To reduce exposure, avoid processing untrusted PDF files with applications that use the pypdf library. If processing untrusted content is necessary, deploy affected applications within a sandboxed environment to contain potential resource exhaustion.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Out of support scope
Lightspeed Corelightspeed-core/lightspeed-stack-rhel9Fix deferred
Lightspeed Corelightspeed-core/rag-tool-cpu-rhel9Fix deferred
Lightspeed Corelightspeed-core/rag-tool-cuda-12.9-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-chatbot-rhel8Out of support scope
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-cuda-rhel9Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-gaudi-rhel9Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-rocm-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2512627pypdf: pypdf: Denial of Service via crafted PDF with large /ToUnicode streams

EPSS

Процентиль: 3%
0.00127
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

ubuntu
24 дня назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumption when pypdf/_cmap.py function parse_bfrange parses unusually large source-code or destination-string tokens in a font /ToUnicode CMap during text extraction. This issue is fixed in 6.15.0.

nvd
24 дня назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumption when pypdf/_cmap.py function parse_bfrange parses unusually large source-code or destination-string tokens in a font /ToUnicode CMap during text extraction. This issue is fixed in 6.15.0.

debian
24 дня назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.15 ...

github
24 дня назад

pypdf: Possible large memory usage for large /ToUnicode streams

EPSS

Процентиль: 3%
0.00127
Низкий

5.5 Medium

CVSS3