CVE-2026-40260: pypdf: Manipulated XMP metadata entity declarations can exhaust RAM
Published Apr 10, 2026
·Updated
Impact
An attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing the XMP metadata.
Patches This has been fixed in pypdf==6.10.0.
Workarounds If you cannot upgrade yet, consider applying the changes from PR #3724.
Other sources
pypdf is a free and open-source pure-python PDF library. In versions prior to 6.10.0, manipulated XMP metadata entity declarations can exhaust RAM. An attacker who exploits this vulnerability can craft a PDF which leads to large memory usage. This requires parsing the XMP metadata. This issue has been fixed in version 6.10.0.
— MITRE
Affected Software
2 affected componentsFixes available
pip/pypdf<6.10.0
6.10.0
Pypdf Project Pypdf<6.10.0
Remediation
Patch Available
Event History
Apr 10, 2026
Advisory Published
via GitHub·08:59 PM
Data Sourced
via GitHub·08:59 PM
DescriptionWeaknessAffected Software
Apr 16, 2026
CVE Published
via MITRE·11:18 PM
Data Sourced
via MITRE·11:18 PM
DescriptionWeakness
Apr 17, 2026
Data Sourced
via NVD·01:17 AM
RemedyDescriptionSeverityWeaknessAffected Software