
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-103000 is a Denial of Service vulnerability in pypdf, a free and open-source pure-Python PDF library, caused by uncontrolled resource consumption when processing crafted PDF files with unusually large alphabetical page-label values. The vulnerability affects all pypdf versions prior to 6.19.0. It was reported by researcher manop55555, analyzed by stefan6419846, and fixed on September 16, 2026, with public disclosure on September 30, 2026. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Red Hat CVE).
The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling) and CWE-400 (Uncontrolled Resource Consumption). The vulnerable code resides in pypdf/_page_labels.py, specifically in the number2uppercase_letter and number2lowercase_letter functions, which generate alphabetical page labels (e.g., A, B, ..., Z, AA, AB, ...) by repeating characters based on a numeric value embedded in the PDF's /Nums structure. A crafted PDF can supply an arbitrarily large /St (start) value for an alphabetical label style (/A or /a), causing the library to attempt generating an extremely long repeated-character string — for example, a value of 15,000 would produce a string of 577+ characters — consuming excessive memory proportional to the input value with no upper bound check (GitHub Advisory, Fix Commit). No authentication or user interaction is required; the vulnerability is triggered simply by an application calling the page label retrieval API on a malicious PDF.
Successful exploitation causes excessive memory consumption in the host application, potentially leading to application unavailability (Denial of Service). There is no impact on confidentiality or integrity — the vulnerability is purely an availability issue. Any application that accepts PDF uploads and retrieves page labels using pypdf is at risk, including web services, document processing pipelines, and PDF management tools (GitHub Advisory, Red Hat CVE).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time (Red Hat CVE). The EPSS score is 0.0, reflecting low current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the attack is network-accessible, requires no privileges or user interaction, and is assessed as automatable by NVD SSVC analysis, making it straightforward to weaponize against exposed PDF-processing services (GitHub Advisory).
/PageLabels) containing a /Nums array that specifies an alphabetical label style (/S /A or /S /a) with an extremely large /St (start) value, such as 15,000 or higher.reader.page_labels or equivalent), which invokes the vulnerable number2uppercase_letter / number2lowercase_letter functions in pypdf/_page_labels.py./St value with no length limit (in versions < 6.19.0), consuming excessive memory and potentially crashing or hanging the application process (GitHub Advisory, Fix Commit).pypdf/_page_labels.py; log entries referencing number2uppercase_letter or number2lowercase_letter functions./St values in the /PageLabels /Nums structure, detectable via PDF forensic tools or manual inspection of the PDF's cross-reference table.The primary remediation is to upgrade pypdf to version 6.19.0 or later, which introduces a MAXIMUM_PAGE_LABEL_LENGTH constant of 512 and raises a ValueError for label values exceeding this limit (pypdf Release). For users unable to upgrade immediately, the fix from PR #4096 can be applied manually to the pypdf/_page_labels.py file (GitHub PR). Additionally, consider implementing OS-level or container memory limits for PDF processing workers, and validating or sandboxing PDF inputs before processing to reduce the blast radius of malicious files (GitHub Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."