Excessive Iteration in PyPDF - #VU141287
Published: August 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to excessive iteration in the CID font width range parser when parsing font width entries with unusually large values in a crafted PDF. A remote attacker can trick the victim into opening a crafted PDF to cause a denial of service.
User interaction is required to open or process the crafted PDF, for example during text extraction.