CVE-2026-48155

MEDIUM WAF: Medium
CVSS 5.5 Published: 2026-05-28
CWE-400

pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires extracting text in layout mode with large character offsets. This vulnerability is fixed in 6.12.0.

WAF Coverage Analysis

Uncontrolled Resource Consumption Medium WAF Coverage

OWASP: A05:2021 Security Misconfiguration

912xxx - DOS Protection

Affected Software

VendorProductVersion
pypdf_projectpypdfup to 6.12.0

References

Back to CVE Database