pypdf: pypdf: Denial of Service via crafted Roman page labels

cve CVE-2026-102993 3 sources, 3 claims · Watch

Red Hat writes:
pypdf: pypdf: Denial of Service via crafted Roman page labels the claim
Severity they disagree
high GitHub advisories
HIGH NVD
moderate Red Hat
CVSS they disagree
7.5 NVD
6.5 Red Hat
Vendor
py-pdf NVD
Product
pypdf NVD
CWE
CWE-400, CWE-770 GitHub advisories
CWE-400, CWE-770 NVD
CWE-770 Red Hat

How far exploitation has got

  1. No public code known
  2. Proof of concept
  3. Proof of concept, verified
  4. A Metasploit module
  5. Exploited in the wild
  6. Used in ransomware campaigns

Why the CVSS differs

MetricNVDRed Hat
Attack vector AVnetwork Nnetwork N
Attack complexity AClow Llow L
Privileges required PRnone Nnone N
User interaction UInone Nrequired R
Scope Sunchanged Uunchanged U
Confidentiality Cnone Nnone N
Integrity Inone Nnone N
Availability Ahigh Hhigh H

Each source scores the same vulnerability from what it judges the attack to need. The rows marked are where they judge it differently.

Timeline

2026-09-30first spoke of it: pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an application retrieves document page labels, consuming large amounts of memory and potentially making the application unavailable. This issue is fixed in version 6.17.0.NVD
2026-09-30first spoke of it: pypdf: pypdf: Denial of Service via crafted Roman page labelsRed Hat
2026-10-01first spoke of it: pypdf: Possible large memory usage when retrieving Roman page labelsGitHub advisories

What it is to other things

affectspypdf_project/pypdf
NVD
made_bypypdf_project
NVD

In words only, so not counted until a person confirms one:

made_bypy_pdf
NVD says “py-pdf”
affectspy_pdf/pypdf
NVD says “py-pdf · pypdf”
Every value, with what each source said and its receipt
PropertySourceSaidMeans here
Affected
affected
GitHub advisoriespip pypdf < 6.17.0; fixed in 6.17.0
receipt
Source
GitHub advisories
Its words
pip pypdf < 6.17.0; fixed in 6.17.0
Read by
field:vulnerabilities[].{package.ecosystem} {package.name} {vulnerable_version_range}; fixed in {first_patched_version}
Said since
2026-10-06 17:39 UTC
Last answered
2026-10-06 17:41 UTC
Original
open at the source
2026-10-06 17:39 UTCpip pypdf < 6.17.0; fixed in 6.17.0
2026-10-02 11:59 UTC—
What the source handed over
{
  "comments": 4,
  "credits": [
    {
      "type": "reporter",
      "user": {
        "avatar_url": "https://avatars.githubusercontent.com/u/169085077?v=4",
        "events_url": "https://api.github.com/users/Nivid42/events{/privacy}",
        "followers_url": "https://api.github.com/users/Nivid42/followers",
        "following_url": "https://api.github.com/users/Nivid42/following{/other_user}",
        "gists_url": "https://api.github.com/users/Nivid42/gists{/gist_id}",
        "gravatar_id": "",
        "html_url": "https://github.com/Nivid42",
        "id": 169085077,
        "login": "Nivid42",
        "node_id": "U_kgDOChQIlQ",
        "organizations_url": "https://api.github.com/users/Nivid42/orgs",
        "received_events_url": "https://api.github.com/users/Nivid42/received_events",
        "repos_url": "https://api.github.com/users/Nivid42/repos",
        "site_admin": false,
        "starred_url": "https://api.github.com/users/Nivid42/starred{/owner}{/repo}",
        "subscriptions_url": "https://api.github.com/users/Nivid42/subscriptions",
        "type": "User",
        "url": "https://api.github.com/users/Nivid42",
        "user_view_type": "public"
      }
    },
    {
      "type": "analyst",
      "user": {
        "avatar_url": "https://avatars.githubusercontent.com/u/96178532?v=4",
        "events_url": "https://api.github.com/users/stefan6419846/events{/privacy}",
        "followers_url": "https://api.github.com/users/stefan6419846/followers",
        "following_url": "https://api.github.com/users/stefan6419846/following{/other_user}",
        "gists_url": "https://api.github.com/users/stefan6419846/gists{/gist_id}",
        "gravatar_id": "",
        "html_url": "https://github.com/stefan6419846",
        "id": 96178532,
        "login": "stefan6419846",
        "node_id": "U_kgDOBbuRZA",
        "organizations_url": "https://api.github.com/users/stefan6419846/orgs",
        "received_events_url": "https://api.github.com/users/stefan6419846/received_events",
        "repos_url": "https://api.github.com/users/stefan6419846/repos",
        "site_admin": false,
        "starred_url": "https://api.github.com/users/stefan6419846/starred{/owner}{/repo}",
        "subscriptions_url": "https://api.github.com/users/stefan6419846/subscriptions",
        "type": "User",
        "url": "https://api.github.com/users/stefan6419846",
        "user_view_type": "public"
      }
    }
  ],
  "cve_id": "CVE-2026-102993",
  "cvss": {
    "score": null,
    "vector_string": null
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 0.0,
      "vector_string": null
    },
    "cvss_v4": {
      "score": 8.7,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-400",
      "name": "Uncontrolled Resource Consumption"
    },
    {
      "cwe_id": "CWE-770",
      "name": "Allocation of Resources Without Limits or Throttling"
    }
  ],
  "description": "### Impact\n\nAn attacker who uses this vulnerability can craft a PDF which leads to large memory consumption. This requires accessing the page labels of a document with large Roman numerals.\n\n### Patches\n\nThis has been fixed in [pypdf==6.17.0](https://github.com/py-pdf/pypdf/releases/tag/6.17.0).\n\n### Workarounds\n\nIf you cannot upgrade yet, consider applying the changes from PR [#4047](https://github.com/py-pdf/pypdf/pull/4047).",
  "epss": {
    "percentage": 0.0035,
    "percentile": 0.26389
  },
  "ghsa_id": "GHSA-qv6h-rv94-w285",
  "github_reviewed_at": "2026-10-01T15:03:45Z",
  "html_url": "https://github.com/advisories/GHSA-qv6h-rv94-w285",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-qv6h-rv94-w285"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-102993"
    }
  ],
  "nvd_published_at": "2026-09-30T20:17:27Z",
  "published_at": "2026-10-01T15:03:45Z",
  "references": [
    "https://github.com/py-pdf/pypdf/security/advisories/GHSA-qv6h-rv94-w285",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-102993",
    "https://github.com/py-pdf/pypdf/pull/4047",
    "https://github.com/py-pdf/pypdf/commit/89db7c4fe9315ecc964bfdf05a4e8c4b94175163",
    "https://github.com/py-pdf/pypdf/releases/tag/6.17.0",
    "https://github.com/advisories/GHSA-qv6h-rv94-w285"
  ],
  "repository_advisory_url": "https://api.github.com/repos/py-pdf/pypdf/security-advisories/GHSA-qv6h-rv94-w285",
  "severity": "high",
  "source_code_location": "https://github.com/py-pdf/pypdf",
  "summary": "pypdf: Possible large memory usage when retrieving Roman page labels",
  "type": "reviewed",
  "updated_at": "2026-10-01T15:03:48Z",
  "url": "https://api.github.com/advisories/GHSA-qv6h-rv94-w285",
  "vulnerabilities": [
    {
      "first_patched_version": "6.17.0",
      "package": {
        "ecosystem": "pip",
        "name": "pypdf"
      },
      "vulnerable_functions": [],
      "vulnerable_version_range": "< 6.17.0"
    }
  ],
  "withdrawn_at": null
}
—
Automatable
automatable
NVDno
At least one of those steps needs a person.
receipt
Source
NVD
Its words
no
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].automatable
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCno
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "pypdf",
            "vendor": "py-pdf",
            "versions": [
              {
                "status": "affected",
                "version": "< 6.17.0"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:pypdf_project:pypdf:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "3E52967B-572F-4CB5-A350-DDD0035B85E0",
                "versionEndExcluding": "6.17.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an application retrieves document page labels, consuming large amounts of memory and potentially making the application unavailable. This issue is fixed in version 6.17.0."
      }
    ],
    "id": "CVE-2026-102993",
    "lastModified": "2026-10-02T17:17:01.203",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.7,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-102993",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-02T16:31:55.843886Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-30T20:17:27.630",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/py-pdf/pypdf/commit/89db7c4fe9315ecc964bfdf05a4e8c4b94175163"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/py-pdf/pypdf/pull/4047"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/py-pdf/pypdf/releases/tag/6.17.0"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch",
          "Vendor Advisory"
        ],
        "url": "https://github.com/py-pdf/pypdf/security/advisories/GHSA-qv6h-rv94-w285"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-400"
          },
          {
            "lang": "en",
            "value": "CWE-770"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
conflict
NVD7.5
receipt
Source
NVD
Its words
7.5
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-02 18:03 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-02 18:03 UTC7.5
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "pypdf",
            "vendor": "py-pdf",
            "versions": [
              {
                "status": "affected",
                "version": "< 6.17.0"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:pypdf_project:pypdf:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "3E52967B-572F-4CB5-A350-DDD0035B85E0",
                "versionEndExcluding": "6.17.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an application retrieves document page labels, consuming large amounts of memory and potentially making the application unavailable. This issue is fixed in version 6.17.0."
      }
    ],
    "id": "CVE-2026-102993",
    "lastModified": "2026-10-02T17:17:01.203",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.7,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-102993",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-02T16:31:55.843886Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-30T20:17:27.630",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/py-pdf/pypdf/commit/89db7c4fe9315ecc964bfdf05a4e8c4b94175163"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/py-pdf/pypdf/pull/4047"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/py-pdf/pypdf/releases/tag/6.17.0"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch",
          "Vendor Advisory"
        ],
        "url": "https://github.com/py-pdf/pypdf/security/advisories/GHSA-qv6h-rv94-w285"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-400"
          },
          {
            "lang": "en",
            "value": "CWE-770"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
conflict
Red Hat6.5
receipt
Source
Red Hat
Its words
6.5
Read by
field:cvss3_score
Said since
2026-10-02 12:01 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-102993",
  "CWE": "CWE-770",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2544269",
  "bugzilla_description": "pypdf: pypdf: Denial of Service via crafted Roman page labels",
  "cvss3_score": "6.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-09-30T19:55:52Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-102993.json",
  "severity": "moderate"
}
—
Cvss4
cvss4
NVD8.7
receipt
Source
NVD
Its words
8.7
Read by
field:cve.metrics.cvssMetricV40[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV40[].cvssData.baseScore
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTC8.7
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "pypdf",
            "vendor": "py-pdf",
            "versions": [
              {
                "status": "affected",
                "version": "< 6.17.0"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:pypdf_project:pypdf:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "3E52967B-572F-4CB5-A350-DDD0035B85E0",
                "versionEndExcluding": "6.17.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an application retrieves document page labels, consuming large amounts of memory and potentially making the application unavailable. This issue is fixed in version 6.17.0."
      }
    ],
    "id": "CVE-2026-102993",
    "lastModified": "2026-10-02T17:17:01.203",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.7,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-102993",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-02T16:31:55.843886Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-30T20:17:27.630",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/py-pdf/pypdf/commit/89db7c4fe9315ecc964bfdf05a4e8c4b94175163"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/py-pdf/pypdf/pull/4047"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/py-pdf/pypdf/releases/tag/6.17.0"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch",
          "Vendor Advisory"
        ],
        "url": "https://github.com/py-pdf/pypdf/security/advisories/GHSA-qv6h-rv94-w285"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-400"
          },
          {
            "lang": "en",
            "value": "CWE-770"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Cvss4 vector
cvss4_vector
NVDCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
receipt
Source
NVD
Its words
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Read by
field:cve.metrics.cvssMetricV40[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV40[].cvssData.vectorString
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "pypdf",
            "vendor": "py-pdf",
            "versions": [
              {
                "status": "affected",
                "version": "< 6.17.0"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:pypdf_project:pypdf:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "3E52967B-572F-4CB5-A350-DDD0035B85E0",
                "versionEndExcluding": "6.17.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an application retrieves document page labels, consuming large amounts of memory and potentially making the application unavailable. This issue is fixed in version 6.17.0."
      }
    ],
    "id": "CVE-2026-102993",
    "lastModified": "2026-10-02T17:17:01.203",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.7,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-102993",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-02T16:31:55.843886Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-30T20:17:27.630",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/py-pdf/pypdf/commit/89db7c4fe9315ecc964bfdf05a4e8c4b94175163"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/py-pdf/pypdf/pull/4047"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/py-pdf/pypdf/releases/tag/6.17.0"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch",
          "Vendor Advisory"
        ],
        "url": "https://github.com/py-pdf/pypdf/security/advisories/GHSA-qv6h-rv94-w285"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-400"
          },
          {
            "lang": "en",
            "value": "CWE-770"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS vector
cvss_vector
not compared
NVDCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
receipt
Source
NVD
Its words
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV31[].cvssData.vectorString
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "pypdf",
            "vendor": "py-pdf",
            "versions": [
              {
                "status": "affected",
                "version": "< 6.17.0"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:pypdf_project:pypdf:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "3E52967B-572F-4CB5-A350-DDD0035B85E0",
                "versionEndExcluding": "6.17.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an application retrieves document page labels, consuming large amounts of memory and potentially making the application unavailable. This issue is fixed in version 6.17.0."
      }
    ],
    "id": "CVE-2026-102993",
    "lastModified": "2026-10-02T17:17:01.203",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.7,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-102993",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-02T16:31:55.843886Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-30T20:17:27.630",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/py-pdf/pypdf/commit/89db7c4fe9315ecc964bfdf05a4e8c4b94175163"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/py-pdf/pypdf/pull/4047"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/py-pdf/pypdf/releases/tag/6.17.0"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch",
          "Vendor Advisory"
        ],
        "url": "https://github.com/py-pdf/pypdf/security/advisories/GHSA-qv6h-rv94-w285"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-400"
          },
          {
            "lang": "en",
            "value": "CWE-770"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS vector
cvss_vector
not compared
Red HatCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
receipt
Source
Red Hat
Its words
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Read by
field:cvss3_scoring_vector
Said since
2026-10-06 13:01 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
2026-10-06 13:01 UTCCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
2026-10-02 12:01 UTC—
What the source handed over
{
  "CVE": "CVE-2026-102993",
  "CWE": "CWE-770",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2544269",
  "bugzilla_description": "pypdf: pypdf: Denial of Service via crafted Roman page labels",
  "cvss3_score": "6.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-09-30T19:55:52Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-102993.json",
  "severity": "moderate"
}
—
CWE
cwe
different words
GitHub advisoriesCWE-400, CWE-770
receipt
Source
GitHub advisories
Its words
CWE-400, CWE-770
Read by
field:cwes[].cwe_id
Said since
2026-10-02 11:59 UTC
Last answered
2026-10-06 17:41 UTC
Original
open at the source
What the source handed over
{
  "comments": 4,
  "credits": [
    {
      "type": "reporter",
      "user": {
        "avatar_url": "https://avatars.githubusercontent.com/u/169085077?v=4",
        "events_url": "https://api.github.com/users/Nivid42/events{/privacy}",
        "followers_url": "https://api.github.com/users/Nivid42/followers",
        "following_url": "https://api.github.com/users/Nivid42/following{/other_user}",
        "gists_url": "https://api.github.com/users/Nivid42/gists{/gist_id}",
        "gravatar_id": "",
        "html_url": "https://github.com/Nivid42",
        "id": 169085077,
        "login": "Nivid42",
        "node_id": "U_kgDOChQIlQ",
        "organizations_url": "https://api.github.com/users/Nivid42/orgs",
        "received_events_url": "https://api.github.com/users/Nivid42/received_events",
        "repos_url": "https://api.github.com/users/Nivid42/repos",
        "site_admin": false,
        "starred_url": "https://api.github.com/users/Nivid42/starred{/owner}{/repo}",
        "subscriptions_url": "https://api.github.com/users/Nivid42/subscriptions",
        "type": "User",
        "url": "https://api.github.com/users/Nivid42",
        "user_view_type": "public"
      }
    },
    {
      "type": "analyst",
      "user": {
        "avatar_url": "https://avatars.githubusercontent.com/u/96178532?v=4",
        "events_url": "https://api.github.com/users/stefan6419846/events{/privacy}",
        "followers_url": "https://api.github.com/users/stefan6419846/followers",
        "following_url": "https://api.github.com/users/stefan6419846/following{/other_user}",
        "gists_url": "https://api.github.com/users/stefan6419846/gists{/gist_id}",
        "gravatar_id": "",
        "html_url": "https://github.com/stefan6419846",
        "id": 96178532,
        "login": "stefan6419846",
        "node_id": "U_kgDOBbuRZA",
        "organizations_url": "https://api.github.com/users/stefan6419846/orgs",
        "received_events_url": "https://api.github.com/users/stefan6419846/received_events",
        "repos_url": "https://api.github.com/users/stefan6419846/repos",
        "site_admin": false,
        "starred_url": "https://api.github.com/users/stefan6419846/starred{/owner}{/repo}",
        "subscriptions_url": "https://api.github.com/users/stefan6419846/subscriptions",
        "type": "User",
        "url": "https://api.github.com/users/stefan6419846",
        "user_view_type": "public"
      }
    }
  ],
  "cve_id": "CVE-2026-102993",
  "cvss": {
    "score": null,
    "vector_string": null
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 0.0,
      "vector_string": null
    },
    "cvss_v4": {
      "score": 8.7,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-400",
      "name": "Uncontrolled Resource Consumption"
    },
    {
      "cwe_id": "CWE-770",
      "name": "Allocation of Resources Without Limits or Throttling"
    }
  ],
  "description": "### Impact\n\nAn attacker who uses this vulnerability can craft a PDF which leads to large memory consumption. This requires accessing the page labels of a document with large Roman numerals.\n\n### Patches\n\nThis has been fixed in [pypdf==6.17.0](https://github.com/py-pdf/pypdf/releases/tag/6.17.0).\n\n### Workarounds\n\nIf you cannot upgrade yet, consider applying the changes from PR [#4047](https://github.com/py-pdf/pypdf/pull/4047).",
  "epss": {
    "percentage": 0.0035,
    "percentile": 0.26389
  },
  "ghsa_id": "GHSA-qv6h-rv94-w285",
  "github_reviewed_at": "2026-10-01T15:03:45Z",
  "html_url": "https://github.com/advisories/GHSA-qv6h-rv94-w285",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-qv6h-rv94-w285"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-102993"
    }
  ],
  "nvd_published_at": "2026-09-30T20:17:27Z",
  "published_at": "2026-10-01T15:03:45Z",
  "references": [
    "https://github.com/py-pdf/pypdf/security/advisories/GHSA-qv6h-rv94-w285",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-102993",
    "https://github.com/py-pdf/pypdf/pull/4047",
    "https://github.com/py-pdf/pypdf/commit/89db7c4fe9315ecc964bfdf05a4e8c4b94175163",
    "https://github.com/py-pdf/pypdf/releases/tag/6.17.0",
    "https://github.com/advisories/GHSA-qv6h-rv94-w285"
  ],
  "repository_advisory_url": "https://api.github.com/repos/py-pdf/pypdf/security-advisories/GHSA-qv6h-rv94-w285",
  "severity": "high",
  "source_code_location": "https://github.com/py-pdf/pypdf",
  "summary": "pypdf: Possible large memory usage when retrieving Roman page labels",
  "type": "reviewed",
  "updated_at": "2026-10-01T15:03:48Z",
  "url": "https://api.github.com/advisories/GHSA-qv6h-rv94-w285",
  "vulnerabilities": [
    {
      "first_patched_version": "6.17.0",
      "package": {
        "ecosystem": "pip",
        "name": "pypdf"
      },
      "vulnerable_functions": [],
      "vulnerable_version_range": "< 6.17.0"
    }
  ],
  "withdrawn_at": null
}
—
CWE
cwe
different words
NVDCWE-400, CWE-770
receipt
Source
NVD
Its words
CWE-400, CWE-770
Read by
field:cve.weaknesses[].description[].value
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCCWE-400, CWE-770
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "pypdf",
            "vendor": "py-pdf",
            "versions": [
              {
                "status": "affected",
                "version": "< 6.17.0"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:pypdf_project:pypdf:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "3E52967B-572F-4CB5-A350-DDD0035B85E0",
                "versionEndExcluding": "6.17.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an application retrieves document page labels, consuming large amounts of memory and potentially making the application unavailable. This issue is fixed in version 6.17.0."
      }
    ],
    "id": "CVE-2026-102993",
    "lastModified": "2026-10-02T17:17:01.203",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.7,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-102993",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-02T16:31:55.843886Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-30T20:17:27.630",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/py-pdf/pypdf/commit/89db7c4fe9315ecc964bfdf05a4e8c4b94175163"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/py-pdf/pypdf/pull/4047"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/py-pdf/pypdf/releases/tag/6.17.0"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch",
          "Vendor Advisory"
        ],
        "url": "https://github.com/py-pdf/pypdf/security/advisories/GHSA-qv6h-rv94-w285"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-400"
          },
          {
            "lang": "en",
            "value": "CWE-770"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CWE
cwe
different words
Red HatCWE-770
receipt
Source
Red Hat
Its words
CWE-770
Read by
field:CWE
Said since
2026-10-02 12:01 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-102993",
  "CWE": "CWE-770",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2544269",
  "bugzilla_description": "pypdf: pypdf: Denial of Service via crafted Roman page labels",
  "cvss3_score": "6.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-09-30T19:55:52Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-102993.json",
  "severity": "moderate"
}
—
Ecosystem
ecosystem
GitHub advisoriespip
receipt
Source
GitHub advisories
Its words
pip
Read by
field:vulnerabilities[].package.ecosystem
Said since
2026-10-02 11:59 UTC
Last answered
2026-10-06 17:41 UTC
Original
open at the source
What the source handed over
{
  "comments": 4,
  "credits": [
    {
      "type": "reporter",
      "user": {
        "avatar_url": "https://avatars.githubusercontent.com/u/169085077?v=4",
        "events_url": "https://api.github.com/users/Nivid42/events{/privacy}",
        "followers_url": "https://api.github.com/users/Nivid42/followers",
        "following_url": "https://api.github.com/users/Nivid42/following{/other_user}",
        "gists_url": "https://api.github.com/users/Nivid42/gists{/gist_id}",
        "gravatar_id": "",
        "html_url": "https://github.com/Nivid42",
        "id": 169085077,
        "login": "Nivid42",
        "node_id": "U_kgDOChQIlQ",
        "organizations_url": "https://api.github.com/users/Nivid42/orgs",
        "received_events_url": "https://api.github.com/users/Nivid42/received_events",
        "repos_url": "https://api.github.com/users/Nivid42/repos",
        "site_admin": false,
        "starred_url": "https://api.github.com/users/Nivid42/starred{/owner}{/repo}",
        "subscriptions_url": "https://api.github.com/users/Nivid42/subscriptions",
        "type": "User",
        "url": "https://api.github.com/users/Nivid42",
        "user_view_type": "public"
      }
    },
    {
      "type": "analyst",
      "user": {
        "avatar_url": "https://avatars.githubusercontent.com/u/96178532?v=4",
        "events_url": "https://api.github.com/users/stefan6419846/events{/privacy}",
        "followers_url": "https://api.github.com/users/stefan6419846/followers",
        "following_url": "https://api.github.com/users/stefan6419846/following{/other_user}",
        "gists_url": "https://api.github.com/users/stefan6419846/gists{/gist_id}",
        "gravatar_id": "",
        "html_url": "https://github.com/stefan6419846",
        "id": 96178532,
        "login": "stefan6419846",
        "node_id": "U_kgDOBbuRZA",
        "organizations_url": "https://api.github.com/users/stefan6419846/orgs",
        "received_events_url": "https://api.github.com/users/stefan6419846/received_events",
        "repos_url": "https://api.github.com/users/stefan6419846/repos",
        "site_admin": false,
        "starred_url": "https://api.github.com/users/stefan6419846/starred{/owner}{/repo}",
        "subscriptions_url": "https://api.github.com/users/stefan6419846/subscriptions",
        "type": "User",
        "url": "https://api.github.com/users/stefan6419846",
        "user_view_type": "public"
      }
    }
  ],
  "cve_id": "CVE-2026-102993",
  "cvss": {
    "score": null,
    "vector_string": null
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 0.0,
      "vector_string": null
    },
    "cvss_v4": {
      "score": 8.7,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-400",
      "name": "Uncontrolled Resource Consumption"
    },
    {
      "cwe_id": "CWE-770",
      "name": "Allocation of Resources Without Limits or Throttling"
    }
  ],
  "description": "### Impact\n\nAn attacker who uses this vulnerability can craft a PDF which leads to large memory consumption. This requires accessing the page labels of a document with large Roman numerals.\n\n### Patches\n\nThis has been fixed in [pypdf==6.17.0](https://github.com/py-pdf/pypdf/releases/tag/6.17.0).\n\n### Workarounds\n\nIf you cannot upgrade yet, consider applying the changes from PR [#4047](https://github.com/py-pdf/pypdf/pull/4047).",
  "epss": {
    "percentage": 0.0035,
    "percentile": 0.26389
  },
  "ghsa_id": "GHSA-qv6h-rv94-w285",
  "github_reviewed_at": "2026-10-01T15:03:45Z",
  "html_url": "https://github.com/advisories/GHSA-qv6h-rv94-w285",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-qv6h-rv94-w285"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-102993"
    }
  ],
  "nvd_published_at": "2026-09-30T20:17:27Z",
  "published_at": "2026-10-01T15:03:45Z",
  "references": [
    "https://github.com/py-pdf/pypdf/security/advisories/GHSA-qv6h-rv94-w285",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-102993",
    "https://github.com/py-pdf/pypdf/pull/4047",
    "https://github.com/py-pdf/pypdf/commit/89db7c4fe9315ecc964bfdf05a4e8c4b94175163",
    "https://github.com/py-pdf/pypdf/releases/tag/6.17.0",
    "https://github.com/advisories/GHSA-qv6h-rv94-w285"
  ],
  "repository_advisory_url": "https://api.github.com/repos/py-pdf/pypdf/security-advisories/GHSA-qv6h-rv94-w285",
  "severity": "high",
  "source_code_location": "https://github.com/py-pdf/pypdf",
  "summary": "pypdf: Possible large memory usage when retrieving Roman page labels",
  "type": "reviewed",
  "updated_at": "2026-10-01T15:03:48Z",
  "url": "https://api.github.com/advisories/GHSA-qv6h-rv94-w285",
  "vulnerabilities": [
    {
      "first_patched_version": "6.17.0",
      "package": {
        "ecosystem": "pip",
        "name": "pypdf"
      },
      "vulnerable_functions": [],
      "vulnerable_version_range": "< 6.17.0"
    }
  ],
  "withdrawn_at": null
}
—
Exploitation
exploitation
NVDnone
No evidence of exploitation, and no public proof of concept.
receipt
Source
NVD
Its words
none
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].exploitation
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCnone
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "pypdf",
            "vendor": "py-pdf",
            "versions": [
              {
                "status": "affected",
                "version": "< 6.17.0"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:pypdf_project:pypdf:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "3E52967B-572F-4CB5-A350-DDD0035B85E0",
                "versionEndExcluding": "6.17.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an application retrieves document page labels, consuming large amounts of memory and potentially making the application unavailable. This issue is fixed in version 6.17.0."
      }
    ],
    "id": "CVE-2026-102993",
    "lastModified": "2026-10-02T17:17:01.203",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.7,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-102993",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-02T16:31:55.843886Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-30T20:17:27.630",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/py-pdf/pypdf/commit/89db7c4fe9315ecc964bfdf05a4e8c4b94175163"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/py-pdf/pypdf/pull/4047"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/py-pdf/pypdf/releases/tag/6.17.0"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch",
          "Vendor Advisory"
        ],
        "url": "https://github.com/py-pdf/pypdf/security/advisories/GHSA-qv6h-rv94-w285"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-400"
          },
          {
            "lang": "en",
            "value": "CWE-770"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Product
product
NVDpypdf
receipt
Source
NVD
Its words
pypdf
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "pypdf",
            "vendor": "py-pdf",
            "versions": [
              {
                "status": "affected",
                "version": "< 6.17.0"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:pypdf_project:pypdf:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "3E52967B-572F-4CB5-A350-DDD0035B85E0",
                "versionEndExcluding": "6.17.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an application retrieves document page labels, consuming large amounts of memory and potentially making the application unavailable. This issue is fixed in version 6.17.0."
      }
    ],
    "id": "CVE-2026-102993",
    "lastModified": "2026-10-02T17:17:01.203",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.7,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-102993",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-02T16:31:55.843886Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-30T20:17:27.630",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/py-pdf/pypdf/commit/89db7c4fe9315ecc964bfdf05a4e8c4b94175163"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/py-pdf/pypdf/pull/4047"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/py-pdf/pypdf/releases/tag/6.17.0"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch",
          "Vendor Advisory"
        ],
        "url": "https://github.com/py-pdf/pypdf/security/advisories/GHSA-qv6h-rv94-w285"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-400"
          },
          {
            "lang": "en",
            "value": "CWE-770"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
conflict
GitHub advisorieshigh
From 7.0 to 8.9.
receipt
Source
GitHub advisories
Its words
high
Read by
field:severity
Said since
2026-10-02 11:59 UTC
Last answered
2026-10-06 17:41 UTC
Original
open at the source
What the source handed over
{
  "comments": 4,
  "credits": [
    {
      "type": "reporter",
      "user": {
        "avatar_url": "https://avatars.githubusercontent.com/u/169085077?v=4",
        "events_url": "https://api.github.com/users/Nivid42/events{/privacy}",
        "followers_url": "https://api.github.com/users/Nivid42/followers",
        "following_url": "https://api.github.com/users/Nivid42/following{/other_user}",
        "gists_url": "https://api.github.com/users/Nivid42/gists{/gist_id}",
        "gravatar_id": "",
        "html_url": "https://github.com/Nivid42",
        "id": 169085077,
        "login": "Nivid42",
        "node_id": "U_kgDOChQIlQ",
        "organizations_url": "https://api.github.com/users/Nivid42/orgs",
        "received_events_url": "https://api.github.com/users/Nivid42/received_events",
        "repos_url": "https://api.github.com/users/Nivid42/repos",
        "site_admin": false,
        "starred_url": "https://api.github.com/users/Nivid42/starred{/owner}{/repo}",
        "subscriptions_url": "https://api.github.com/users/Nivid42/subscriptions",
        "type": "User",
        "url": "https://api.github.com/users/Nivid42",
        "user_view_type": "public"
      }
    },
    {
      "type": "analyst",
      "user": {
        "avatar_url": "https://avatars.githubusercontent.com/u/96178532?v=4",
        "events_url": "https://api.github.com/users/stefan6419846/events{/privacy}",
        "followers_url": "https://api.github.com/users/stefan6419846/followers",
        "following_url": "https://api.github.com/users/stefan6419846/following{/other_user}",
        "gists_url": "https://api.github.com/users/stefan6419846/gists{/gist_id}",
        "gravatar_id": "",
        "html_url": "https://github.com/stefan6419846",
        "id": 96178532,
        "login": "stefan6419846",
        "node_id": "U_kgDOBbuRZA",
        "organizations_url": "https://api.github.com/users/stefan6419846/orgs",
        "received_events_url": "https://api.github.com/users/stefan6419846/received_events",
        "repos_url": "https://api.github.com/users/stefan6419846/repos",
        "site_admin": false,
        "starred_url": "https://api.github.com/users/stefan6419846/starred{/owner}{/repo}",
        "subscriptions_url": "https://api.github.com/users/stefan6419846/subscriptions",
        "type": "User",
        "url": "https://api.github.com/users/stefan6419846",
        "user_view_type": "public"
      }
    }
  ],
  "cve_id": "CVE-2026-102993",
  "cvss": {
    "score": null,
    "vector_string": null
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 0.0,
      "vector_string": null
    },
    "cvss_v4": {
      "score": 8.7,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-400",
      "name": "Uncontrolled Resource Consumption"
    },
    {
      "cwe_id": "CWE-770",
      "name": "Allocation of Resources Without Limits or Throttling"
    }
  ],
  "description": "### Impact\n\nAn attacker who uses this vulnerability can craft a PDF which leads to large memory consumption. This requires accessing the page labels of a document with large Roman numerals.\n\n### Patches\n\nThis has been fixed in [pypdf==6.17.0](https://github.com/py-pdf/pypdf/releases/tag/6.17.0).\n\n### Workarounds\n\nIf you cannot upgrade yet, consider applying the changes from PR [#4047](https://github.com/py-pdf/pypdf/pull/4047).",
  "epss": {
    "percentage": 0.0035,
    "percentile": 0.26389
  },
  "ghsa_id": "GHSA-qv6h-rv94-w285",
  "github_reviewed_at": "2026-10-01T15:03:45Z",
  "html_url": "https://github.com/advisories/GHSA-qv6h-rv94-w285",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-qv6h-rv94-w285"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-102993"
    }
  ],
  "nvd_published_at": "2026-09-30T20:17:27Z",
  "published_at": "2026-10-01T15:03:45Z",
  "references": [
    "https://github.com/py-pdf/pypdf/security/advisories/GHSA-qv6h-rv94-w285",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-102993",
    "https://github.com/py-pdf/pypdf/pull/4047",
    "https://github.com/py-pdf/pypdf/commit/89db7c4fe9315ecc964bfdf05a4e8c4b94175163",
    "https://github.com/py-pdf/pypdf/releases/tag/6.17.0",
    "https://github.com/advisories/GHSA-qv6h-rv94-w285"
  ],
  "repository_advisory_url": "https://api.github.com/repos/py-pdf/pypdf/security-advisories/GHSA-qv6h-rv94-w285",
  "severity": "high",
  "source_code_location": "https://github.com/py-pdf/pypdf",
  "summary": "pypdf: Possible large memory usage when retrieving Roman page labels",
  "type": "reviewed",
  "updated_at": "2026-10-01T15:03:48Z",
  "url": "https://api.github.com/advisories/GHSA-qv6h-rv94-w285",
  "vulnerabilities": [
    {
      "first_patched_version": "6.17.0",
      "package": {
        "ecosystem": "pip",
        "name": "pypdf"
      },
      "vulnerable_functions": [],
      "vulnerable_version_range": "< 6.17.0"
    }
  ],
  "withdrawn_at": null
}
—
Severity
severity
conflict
NVDHIGH
From 7.0 to 8.9.
receipt
Source
NVD
Its words
HIGH
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseSeverity || field:cve.metrics.cvssMetricV31[].cvssData.baseSeverity
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCHIGH
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "pypdf",
            "vendor": "py-pdf",
            "versions": [
              {
                "status": "affected",
                "version": "< 6.17.0"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:pypdf_project:pypdf:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "3E52967B-572F-4CB5-A350-DDD0035B85E0",
                "versionEndExcluding": "6.17.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an application retrieves document page labels, consuming large amounts of memory and potentially making the application unavailable. This issue is fixed in version 6.17.0."
      }
    ],
    "id": "CVE-2026-102993",
    "lastModified": "2026-10-02T17:17:01.203",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.7,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-102993",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-02T16:31:55.843886Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-30T20:17:27.630",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/py-pdf/pypdf/commit/89db7c4fe9315ecc964bfdf05a4e8c4b94175163"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/py-pdf/pypdf/pull/4047"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/py-pdf/pypdf/releases/tag/6.17.0"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch",
          "Vendor Advisory"
        ],
        "url": "https://github.com/py-pdf/pypdf/security/advisories/GHSA-qv6h-rv94-w285"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-400"
          },
          {
            "lang": "en",
            "value": "CWE-770"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
high
Severity
severity
conflict
Red Hatmoderate
A flaw that is harder to exploit, or whose impact is limited.
receipt
Source
Red Hat
Its words
moderate
Read by
field:severity
Said since
2026-10-02 12:01 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-102993",
  "CWE": "CWE-770",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2544269",
  "bugzilla_description": "pypdf: pypdf: Denial of Service via crafted Roman page labels",
  "cvss3_score": "6.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-09-30T19:55:52Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-102993.json",
  "severity": "moderate"
}
medium
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-10-02 18:03 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-02 18:03 UTCAnalyzed
2026-10-02 12:00 UTCUndergoing Analysis
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "pypdf",
            "vendor": "py-pdf",
            "versions": [
              {
                "status": "affected",
                "version": "< 6.17.0"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:pypdf_project:pypdf:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "3E52967B-572F-4CB5-A350-DDD0035B85E0",
                "versionEndExcluding": "6.17.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an application retrieves document page labels, consuming large amounts of memory and potentially making the application unavailable. This issue is fixed in version 6.17.0."
      }
    ],
    "id": "CVE-2026-102993",
    "lastModified": "2026-10-02T17:17:01.203",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.7,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-102993",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-02T16:31:55.843886Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-30T20:17:27.630",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/py-pdf/pypdf/commit/89db7c4fe9315ecc964bfdf05a4e8c4b94175163"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/py-pdf/pypdf/pull/4047"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/py-pdf/pypdf/releases/tag/6.17.0"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch",
          "Vendor Advisory"
        ],
        "url": "https://github.com/py-pdf/pypdf/security/advisories/GHSA-qv6h-rv94-w285"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-400"
          },
          {
            "lang": "en",
            "value": "CWE-770"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Technical impact
technical_impact
NVDpartial
The attacker gains limited control, or limited information.
receipt
Source
NVD
Its words
partial
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].technicalImpact
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCpartial
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "pypdf",
            "vendor": "py-pdf",
            "versions": [
              {
                "status": "affected",
                "version": "< 6.17.0"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:pypdf_project:pypdf:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "3E52967B-572F-4CB5-A350-DDD0035B85E0",
                "versionEndExcluding": "6.17.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an application retrieves document page labels, consuming large amounts of memory and potentially making the application unavailable. This issue is fixed in version 6.17.0."
      }
    ],
    "id": "CVE-2026-102993",
    "lastModified": "2026-10-02T17:17:01.203",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.7,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-102993",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-02T16:31:55.843886Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-30T20:17:27.630",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/py-pdf/pypdf/commit/89db7c4fe9315ecc964bfdf05a4e8c4b94175163"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/py-pdf/pypdf/pull/4047"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/py-pdf/pypdf/releases/tag/6.17.0"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch",
          "Vendor Advisory"
        ],
        "url": "https://github.com/py-pdf/pypdf/security/advisories/GHSA-qv6h-rv94-w285"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-400"
          },
          {
            "lang": "en",
            "value": "CWE-770"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDpy-pdf
receipt
Source
NVD
Its words
py-pdf
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "pypdf",
            "vendor": "py-pdf",
            "versions": [
              {
                "status": "affected",
                "version": "< 6.17.0"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:pypdf_project:pypdf:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "3E52967B-572F-4CB5-A350-DDD0035B85E0",
                "versionEndExcluding": "6.17.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an application retrieves document page labels, consuming large amounts of memory and potentially making the application unavailable. This issue is fixed in version 6.17.0."
      }
    ],
    "id": "CVE-2026-102993",
    "lastModified": "2026-10-02T17:17:01.203",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.7,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-102993",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-02T16:31:55.843886Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-30T20:17:27.630",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/py-pdf/pypdf/commit/89db7c4fe9315ecc964bfdf05a4e8c4b94175163"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/py-pdf/pypdf/pull/4047"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/py-pdf/pypdf/releases/tag/6.17.0"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch",
          "Vendor Advisory"
        ],
        "url": "https://github.com/py-pdf/pypdf/security/advisories/GHSA-qv6h-rv94-w285"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-400"
          },
          {
            "lang": "en",
            "value": "CWE-770"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Every claim, by kind

vulnerability

pypdf: pypdf: Denial of Service via crafted Roman page labels
zetlyn/cve-redhat · 2026-09-30
cvss 6.5 cvss_vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H cwe CWE-770 severity moderate source
pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an application retrieves document page labels, consuming large amounts of memory and potentially making the application unavailable. This issue is fixed in version 6.17.0.
zetlyn/cve-nvd · 2026-09-30
automatable no cvss 7.5 cvss4 8.7 cvss4_vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X cvss_vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H cwe CWE-400, CWE-770 exploitation none product pypdf severity HIGH status Analyzed technical_impact partial vendor py-pdf source
pypdf: Possible large memory usage when retrieving Roman page labels
zetlyn/cve-ghsa · 2026-10-01
affected pip pypdf < 6.17.0; fixed in 6.17.0 cwe CWE-400, CWE-770 ecosystem pip severity high source