Resource exhaustion in PyPDF - #VU149047
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the parser for the /Widths entry of TrueType and Type1 fonts when parsing PDF font data. A remote attacker can supply a crafted PDF with unusually large width values to cause a denial of service.