Vulnerability DatabaseCVE-2026-103000

CVE-2026-103000: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-103000 is a Denial of Service vulnerability in pypdf, a free and open-source pure-Python PDF library, caused by uncontrolled resource consumption when processing crafted PDF files with unusually large alphabetical page-label values. The vulnerability affects all pypdf versions prior to 6.19.0. It was reported by researcher manop55555, analyzed by stefan6419846, and fixed on September 16, 2026, with public disclosure on September 30, 2026. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling) and CWE-400 (Uncontrolled Resource Consumption). The vulnerable code resides in pypdf/_page_labels.py, specifically in the number2uppercase_letter and number2lowercase_letter functions, which generate alphabetical page labels (e.g., A, B, ..., Z, AA, AB, ...) by repeating characters based on a numeric value embedded in the PDF's /Nums structure. A crafted PDF can supply an arbitrarily large /St (start) value for an alphabetical label style (/A or /a), causing the library to attempt generating an extremely long repeated-character string — for example, a value of 15,000 would produce a string of 577+ characters — consuming excessive memory proportional to the input value with no upper bound check (GitHub Advisory, Fix Commit). No authentication or user interaction is required; the vulnerability is triggered simply by an application calling the page label retrieval API on a malicious PDF.

Impact

Successful exploitation causes excessive memory consumption in the host application, potentially leading to application unavailability (Denial of Service). There is no impact on confidentiality or integrity — the vulnerability is purely an availability issue. Any application that accepts PDF uploads and retrieves page labels using pypdf is at risk, including web services, document processing pipelines, and PDF management tools (GitHub Advisory, Red Hat CVE).

Exploitability

No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time (Red Hat CVE). The EPSS score is 0.0, reflecting low current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the attack is network-accessible, requires no privileges or user interaction, and is assessed as automatable by NVD SSVC analysis, making it straightforward to weaponize against exposed PDF-processing services (GitHub Advisory).

Exploitation steps

  1. Craft a malicious PDF: Create a PDF file with a page label dictionary (/PageLabels) containing a /Nums array that specifies an alphabetical label style (/S /A or /S /a) with an extremely large /St (start) value, such as 15,000 or higher.
  2. Deliver the PDF: Submit the crafted PDF to a target application that uses pypdf for PDF processing — for example, by uploading it through a web form, API endpoint, or email attachment handler.
  3. Trigger page label retrieval: Ensure the application calls pypdf's page label retrieval functionality (e.g., accessing reader.page_labels or equivalent), which invokes the vulnerable number2uppercase_letter / number2lowercase_letter functions in pypdf/_page_labels.py.
  4. Cause memory exhaustion: The library attempts to generate a string of repeated characters proportional to the large /St value with no length limit (in versions < 6.19.0), consuming excessive memory and potentially crashing or hanging the application process (GitHub Advisory, Fix Commit).

Indicators of compromise

  • Network: Repeated PDF upload requests from the same source IP, particularly with small file sizes but triggering high memory usage on the server.
  • Process: Sudden spike in memory consumption by the Python process handling PDF parsing; process OOM (Out of Memory) kills or application crashes correlated with PDF ingestion events.
  • Logs: Application error logs showing memory errors or unhandled exceptions originating from pypdf/_page_labels.py; log entries referencing number2uppercase_letter or number2lowercase_letter functions.
  • File System: Presence of suspicious PDF files with abnormally large /St values in the /PageLabels /Nums structure, detectable via PDF forensic tools or manual inspection of the PDF's cross-reference table.

Mitigation and workarounds

The primary remediation is to upgrade pypdf to version 6.19.0 or later, which introduces a MAXIMUM_PAGE_LABEL_LENGTH constant of 512 and raises a ValueError for label values exceeding this limit (pypdf Release). For users unable to upgrade immediately, the fix from PR #4096 can be applied manually to the pypdf/_page_labels.py file (GitHub PR). Additionally, consider implementing OS-level or container memory limits for PDF processing workers, and validating or sandboxing PDF inputs before processing to reduce the blast radius of malicious files (GitHub Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

pypdf2

Affected

sid

pypdf: 6.19.0-1

Fixed

trixie

pypdf

Affected

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
GHSA-jqmf-mx4f-hfr6CRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
GHSA-8mcx-5rqc-vhmfHIGH8.8
  • Python logoPython
  • dulwich
NoYesOct 02, 2026
GHSA-5rmq-chc7-m22fHIGH7.5
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
GHSA-35mr-4567-66vgMEDIUM6.5
  • Python logoPython
  • dulwich
NoYesOct 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management