
CVE-2026-40260 pypdf is a free and open-source pure-python PDF library. In versions prior to 6.10.0, manipulated XMP metadata entity declarations can exhaust RAM. An attacker who ex… https://www.cve.org/CVERecord?id=CVE-2026-40260
Post summary
The post announces that CVE‑2026‑40260 in pypdf allows memory exhaustion through manipulated XMP metadata in versions before 6.10.0.


