Description
pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires extracting text in layout mode with large character offsets. This vulnerability is fixed in 6.12.0.
Problem types
CWE-400: Uncontrolled Resource Consumption
Product status
References
github.com/.../pypdf/security/advisories/GHSA-cj93-chg6-vgv8
github.com/py-pdf/pypdf/pull/3790
github.com/py-pdf/pypdf/releases/tag/6.12.0