PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-71870 py-pdf CVE debrief

A crafted PDF can cause large memory consumption in pypdf when parsing unusually large source-code or destination-string tokens in a font /ToUnicode CMap during text extraction. This issue is fixed in pypdf version 6.15.0. The vulnerability affects pypdf, a widely used PDF library, and could lead to large memory consumption and potential denial-of-service (DoS) when parsing crafted PDFs. Defenders should prioritize verifying and updating their pypdf versions, especially in environments where PDF processing is common.

Vendor
py-pdf
Product
pypdf
CVSS
MEDIUM 4.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-07
Original CVE updated
2026-09-09
Advisory published
2026-08-07
Advisory updated
2026-09-09

Who should care

Defenders responsible for PDF processing applications, developers using pypdf, and teams managing software dependencies should assess exposure and prioritize updates. Defenders should care about CVE-2026-71870 because it affects pypdf, a widely used PDF library, and could lead to large memory consumption and potential denial-of-service (DoS) when parsing crafted PDFs. The vulnerability is fixed in version 6.15.0, and defenders should prioritize verifying

Why it matters

Defenders should care about CVE-2026-71870 because it affects pypdf, a widely used PDF library, and could lead to large memory consumption and potential denial-of-service (DoS) when parsing crafted PDFs. The vulnerability is fixed in version 6.15.0, and defenders should prioritize verifying and updating their pypdf versions, especially in environments where PDF processing is common.

  • Potential for denial-of-service (DoS) due to large memory consumption
  • Need for verification of pypdf version and exposure in PDF processing workflows
  • Priority for updating to version 6.15.0 or later to mitigate the vulnerability

Technical summary

The pypdf library, prior to version 6.15.0, is vulnerable to large memory consumption when parsing crafted PDFs with unusually large source-code or destination-string tokens in a font /ToUnicode CMap during text extraction. This issue can lead to potential denial-of-service (DoS) and defenders should prioritize verifying and updating pypdf to version 6.15.0 or later, especially in environments where PDF processing is common. The vulnerability is fixed in version 6.15.0, and defenders should review PDF processing workflows for potential exposure.

Defensive priority

Defenders should prioritize verifying and updating pypdf to version 6.15.0 or later, especially in environments where PDF processing is common.

Recommended defensive actions

  • Verify pypdf version and update to 6.15.0 or later
  • Review PDF processing workflows for potential exposure
  • Monitor for unusual memory consumption in pypdf applications
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Review compensating controls for exposed systems while remediation is scheduled and verified

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but additional information on potential exploitation or impact is limited. There is no evidence of public exploitation or widespread impact, but defenders should verify pypdf version and exposure in PDF processing workflows. The vulnerability is fixed in version 6.15.0, and defenders should prioritize verifying and updating their pypdf versions.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-71870 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-71870

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-71870 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-71870

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.