Junglewise Threat Intelligence

CVE-2026-48155: py-pdf pypdf uncontrolled resource consumption in layout mode text extraction

CVE-2026-48155 · Severity: medium · CVSS 4 · Published 2026-05-28

Technologies: Py-Pdf Pypdf. Vendors: PyPI.

Executive brief

pypdf is a widely used Python library for manipulating PDF files. A vulnerability exists where a specially crafted PDF file can cause the library to consume excessive amounts of memory when extracting text in layout mode. This could lead to a denial-of-service condition, potentially crashing applications or services that process untrusted PDF documents.

Technical details

A vulnerability classified as CWE-400 (Uncontrolled Resource Consumption) exists in pypdf versions prior to 6.12.0. The issue occurs during text extraction in 'layout mode' when encountering large character offsets. An attacker can exploit this by providing a maliciously crafted PDF file that, when processed, triggers excessive memory allocation. This is a local attack requiring passive user interaction (opening or processing the file). The vulnerability has been addressed in version 6.12.0 by improving how offsets are handled during layout extraction.

Affected products

  • py-pdf pypdf < 6.12.0

Timeline

  • 2026-05-21: disclosed
  • 2026-05-28: advisory: NVD publication
  • 2026-06-12: patched: GitHub Advisory published and version 6.12.0 released

References

Related threats