THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-fp3f-mc75-235c (medium) — pypdf: Possible large memory usage for large /ToUnicode streams

[GHSA] GHSA-fp3f-mc75-235c (medium) — pypdf: Possible large memory usage for large /ToUnicode streams

medgithub_advisoriesPublished 2026-08-07

GHSA-fp3f-mc75-235c Severity: medium CVE: CVE-2026-71870

pypdf: Possible large memory usage for large /ToUnicode streams

### Impact

An attacker who uses this vulnerability can craft a PDF which leads to large memory consumption. This requires parsing the `/ToUnicode` entry of a font with unusually large values, for example during text extraction.

### Patches

This has been fixed in [pypdf==6.1

Indicators of compromise

Original source: https://github.com/advisories/GHSA-fp3f-mc75-235c