GHSA-fp3f-mc75-235c: Pip/pypdf vulnerability
Impact
An attacker who uses this vulnerability can craft a PDF which leads to large memory consumption. This requires parsing the /ToUnicode entry of a font with unusually large values, for example during text extraction.
Patches
This has been fixed in pypdf==6.15.0.
Workarounds
If you cannot upgrade yet, consider applying the changes from PR #3944.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/pypdfto a version that resolves this vulnerability.Fixed in 6.15.0 - Upgrade
Upgrade
pypdfto a version that resolves this vulnerability.Fixed in 6.15.0 - Compensating control
If you cannot upgrade, apply the changes from PR [#3944] from the pypdf repository (py-pdf/pypdf pull request 3944) to mitigate large memory consumption when parsing the `/ToUnicode` entry of a font with unusually large values during PDF text extraction.
Event History
Frequently Asked Questions
What is the severity of GHSA-fp3f-mc75-235c?
The severity of GHSA-fp3f-mc75-235c is rated as a risk level of 26.
How do I fix GHSA-fp3f-mc75-235c?
To fix GHSA-fp3f-mc75-235c, upgrade to pypdf version 6.15.0 or later.
What type of attack is associated with GHSA-fp3f-mc75-235c?
GHSA-fp3f-mc75-235c is associated with a memory consumption attack through specially crafted PDFs.
Which software is affected by GHSA-fp3f-mc75-235c?
The vulnerability GHSA-fp3f-mc75-235c affects the pypdf software package.
When was the GHSA-fp3f-mc75-235c vulnerability published?
The GHSA-fp3f-mc75-235c vulnerability was published on August 7, 2026.