CVE-2026-102993EPSS p26.4%
CVE-2026-102993CVE-2026-102993
pypdf_project / pypdf
Description
pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an application retrieves document page labels, consuming large amounts of memory and potentially making the application unavailable. This issue is fixed in version 6.17.0.
Scoring
| CVSS | 7.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| EPSS | 0.35% probability of exploitation · percentile 26.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-10-02 |