Resource exhaustion in PyPDF - #VU149048
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to consume large amounts of memory.
The vulnerability exists due to uncontrolled resource consumption in PyPDF\'s handling of /ToUnicode entries in fonts when parsing unusually large values. A remote attacker can supply a crafted PDF containing unusually large /ToUnicode values to consume large amounts of memory.
This can occur during text extraction.