What is CVE-2026-71852?
CVE-2026-71852 is a vulnerability in the pypdf library where a crafted PDF can cause excessive CPU and memory consumption during text extraction via the `Font._collect_cid_character_widths` function. It affects pypdf versions prior to 6.15.0. Upgrading to version 6.15.0 or later is recommended.
Azərbaycanca: CVE-2026-71852 pypdf kitabxanasında xüsusi hazırlanmış PDF faylları vasitəsilə mətn çıxarışı zamanı `Font._collect_cid_character_widths` funksiyasında həddindən artıq CPU və yaddaş istifadəsinə səbəb olan zəiflikdir. Bu, 6.15.0 versiyasından əvvəlki pypdf istifadəçilərinə təsir edir. Kitabxananı ən azı 6.15.0 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
In which function of the pypdf library does CVE-2026-71852 occur?
The vulnerability occurs in the `Font._collect_cid_character_widths` function.
To mitigate this vulnerability, which version of pypdf should I upgrade to?
It is recommended to upgrade the pypdf library to version 6.15.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.