SB2026052521 - Denial of service in PyPDF



SB2026052521 - Denial of service in PyPDF

Published: May 25, 2026

Security Bulletin ID SB2026052521
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-48735)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause excessive memory consumption.

The vulnerability exists due to allocation of resources without limits or throttling in the XMP metadata parser when parsing large XMP metadata streams in a PDF file. A remote attacker can supply a specially crafted PDF file to cause excessive memory consumption.


Remediation

Install update from vendor's website.