Hi, The following vulnerabilities were published for pypdf. CVE-2026-71852[0]: | pypdf is a free and open-source pure-python PDF library. Prior to | 6.15.0, a crafted PDF can cause long runtimes and large memory | consumption when pypdf/_font.py function | Font._collect_cid_character_widths expands unusually large CID font | /W width ranges or excessive width entries during text extraction. | This issue is fixed in 6.15.0. CVE-2026-71870[1]: | pypdf is a free and open-source pure-python PDF library. Prior to | 6.15.0, a crafted PDF can cause large memory consumption when | pypdf/_cmap.py function parse_bfrange parses unusually large source- | code or destination-string tokens in a font /ToUnicode CMap during | text extraction. This issue is fixed in 6.15.0. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-71852 https://www.cve.org/CVERecord?id=CVE-2026-71852 [1] https://security-tracker.debian.org/tracker/CVE-2026-71870 https://www.cve.org/CVERecord?id=CVE-2026-71870 Regards, Salvatore