PT-2026-103585 · Pypi · Pypdf

CVE-2026-102994

·

Published

2026-09-30

·

Updated

2026-10-01

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions pypdf versions prior to 6.18.0
Description A flaw in the way the library handles crafted PDF files can lead to uncontrolled resource consumption. Specifically, when a PDF contains indirect-object identifiers or generation-number tokens that persist for a long duration without whitespace, the read until whitespace function within pypdf/ reader.py and pypdf/generic/ base.py scans excessive input. This results in long runtimes and can lead to application unavailability.
Recommendations Update to version 6.18.0.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102994

Affected Products

Pypdf