GHSA-fwg2-594c-jp42: Pip/pypdf vulnerability
Impact
An attacker who uses this vulnerability can craft a PDF which leads to long runtimes and large memory consumption. This requires parsing the font width entries of a font with unusually large values, for example during text extraction.
Patches
This has been fixed in pypdf==6.15.0.
Workarounds
If you cannot upgrade yet, consider applying the changes from PR #3946.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/pypdfto a version that resolves this vulnerability.Fixed in 6.15.0 - Upgrade
Upgrade
py-pdf/pypdfto a version that resolves this vulnerability.Fixed in 6.15.0 - Compensating control
If you cannot upgrade yet, apply the changes from PR [#3946] (py-pdf/pypdf/pull/3946) as a workaround.
Event History
Frequently Asked Questions
What is the severity of GHSA-fwg2-594c-jp42?
The severity of GHSA-fwg2-594c-jp42 is rated as 26, indicating a significant risk due to potential memory consumption and long runtimes.
How do I fix GHSA-fwg2-594c-jp42?
To fix GHSA-fwg2-594c-jp42, upgrade your pypdf package to version 6.15.0 or later.
What are the consequences of GHSA-fwg2-594c-jp42 if left unpatched?
If left unpatched, GHSA-fwg2-594c-jp42 can lead to performance issues such as excessive memory usage and prolonged processing times when handling certain PDF files.
What software is affected by GHSA-fwg2-594c-jp42?
GHSA-fwg2-594c-jp42 affects the pypdf software package.
When was GHSA-fwg2-594c-jp42 published?
GHSA-fwg2-594c-jp42 was published on August 7, 2026.