PT-2026-103589 · Pypi · Pypdf

CVE-2026-102998

·

Published

2026-09-30

·

Updated

2026-10-01

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions pypdf versions prior to 6.19.0
Description A crafted PDF containing specific form field values can trigger a performance issue during appearance-stream generation within the pypdf/generic/ appearance stream.py file. This occurs when an application updates fields with flattening enabled, causing the system to repeat invariant selection-data work inside a loop. This inefficiency leads to excessive runtimes and can result in application unavailability.
Recommendations Update to version 6.19.0.

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102998

Affected Products

Pypdf