PT-2026-103585 · Pypi · Pypdf
CVE-2026-102994
·
Published
2026-09-30
·
Updated
2026-10-01
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
pypdf versions prior to 6.18.0
Description
A flaw in the way the library handles crafted PDF files can lead to uncontrolled resource consumption. Specifically, when a PDF contains indirect-object identifiers or generation-number tokens that persist for a long duration without whitespace, the
read until whitespace function within pypdf/ reader.py and pypdf/generic/ base.py scans excessive input. This results in long runtimes and can lead to application unavailability.Recommendations
Update to version 6.18.0.
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pypdf