CVE-2026-71870EPSS p2.9%
CVE-2026-71870CVE-2026-71870
Description
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumption when pypdf/_cmap.py function parse_bfrange parses unusually large source-code or destination-string tokens in a font /ToUnicode CMap during text extraction. This issue is fixed in 6.15.0.
Scoring
| EPSS | 0.13% probability of exploitation · percentile 2.9% · 2026-08-08T12:02:54Z |
| Last modified | 2026-08-07 |