CVE-2026-48735: pypdf: Manipulated XMP metadata streams can exhaust RAM
Impact
An attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing large XMP metadata, possibly with lots of unnecessary elements.
Patches This has been fixed in pypdf==6.12.1.
Workarounds If you cannot upgrade yet, consider applying the changes from PR #3796.
Other sources
pypdf is a free and open-source pure-python PDF library. Prior to 6.12.1, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing large XMP metadata, possibly with lots of unnecessary elements. This vulnerability is fixed in 6.12.1.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/pypdfto a version that resolves this vulnerability.Fixed in 6.12.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48735?
CVE-2026-48735 has a medium severity rating of 6.9.
What is the risk associated with CVE-2026-48735?
The risk level for CVE-2026-48735 is categorized as a 38.
How do I fix CVE-2026-48735?
To fix CVE-2026-48735, update to pypdf version 6.12.1 or later.
What kind of attack does CVE-2026-48735 allow?
CVE-2026-48735 allows an attacker to craft a PDF that can exhaust system RAM.
What software is affected by CVE-2026-48735?
CVE-2026-48735 affects the pypdf library in versions prior to 6.12.1.