{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-103000/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:pypdf:pypdf:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-103000"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["pypdf (\u003c 6.19.0)","pypdf (\u003c 6.18.1)"],"_cs_severities":["medium"],"_cs_tags":["denial-of-service","pypdf","memory-exhaustion","cve-2026-103000"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe pypdf library contains a vulnerability, identified as CVE-2026-103000, that exposes applications to a denial-of-service (DoS) condition. The issue resides in the handling of alphabetical page labels within PDF documents. When the library processes a document containing specifically crafted, excessively large alphabetical page labels, it triggers a disproportionate increase in memory usage. This can lead to service instability, resource exhaustion, or application crashes depending on the environment where the library is deployed. This vulnerability affects all versions of pypdf prior to 6.19.0. Organizations using pypdf to process untrusted or user-uploaded PDF files are at risk and should prioritize upgrading to the patched version or applying the recommended code changes.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a denial-of-service state for the application processing the malicious PDF. This is particularly concerning for document management systems, web scrapers, or any automated pipeline that parses user-provided PDFs. If the host environment has constrained memory, a single crafted file could induce a crash, disrupting service availability.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the pypdf library to version 6.19.0 or later immediately to incorporate the patch for CVE-2026-103000.\u003c/li\u003e\n\u003cli\u003eIf an immediate upgrade is not possible, apply the code changes provided in the vendor pull request (PR #4096) to sanitize or limit the processing of page labels.\u003c/li\u003e\n\u003cli\u003eImplement memory limits (e.g., cgroups, container memory limits) on processes responsible for parsing untrusted PDF files to mitigate the impact of potential resource exhaustion attacks.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T20:23:24Z","date_published":"2026-10-01T20:23:09Z","id":"https://feed.craftedsignal.io/briefs/2026-10-pypdf-memory-exhaustion/","summary":"A vulnerability in the pypdf library, tracked as CVE-2026-103000, allows attackers to trigger excessive memory consumption and potential denial of service by providing crafted PDFs with large alphabetical page labels.","title":"pypdf Memory Exhaustion Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-10-pypdf-memory-exhaustion/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-103000","version":"https://jsonfeed.org/version/1.1"}