Description
pypdf is a free and open-source pure-python PDF library. Prior to 6.18.0, a crafted PDF containing indirect-object identifiers or generation-number tokens that continue for a long time without whitespace can cause pypdf/_reader.py and pypdf/generic/_base.py to scan excessive input through read_until_whitespace, resulting in long runtimes and application unavailability. This issue is fixed in version 6.18.0.
Published: 2026-09-30
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Denial of Service via resource exhaustion
Action: Immediate Patch
AI Analysis

Impact

pypdf, a pure‑Python PDF library, can be made to spend an excessive amount of time and memory parsing a PDF that contains unusually long indirect‑object identifiers or generation‑number tokens without intervening whitespace. The library’s read_until_whitespace routine then scans a large chunk of input, which can lead to prolonged execution times and application unavailability. The flaw represents uncontrolled resource consumption ( unexplained resource exhaustion (CWE‑407).

Affected Systems

The vulnerability affects the py‑pdf:pypdf library in all releases older than 6.18.0. Any Python application that imports pypdf to read, merge, or otherwise process PDFs could be impacted when it receives a specially crafted document.

Risk and Exploitability

With a CVSS score of 8.7 the issue is considered high severity. No EPSS value is available and it is not listed in the CISA KEV catalog. Attackers can supply a malicious PDF to an application using pypdf; the library will then consume significant CPU and memory, potentially exhausting system resources and causing a denial of service. The attack vector is local or remote depending on how the application receives PDF content. No immediate code‑execution vector exists, but the resource exhaustion can degrade availability for legitimate users.

Generated by OpenCVE AI on September 30, 2026 at 22:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the pypdf library to version 6.18.0 or later to eliminate the excessive scanning of long token sequences.
  • If an application cannot be upgraded immediately, enforce an upper bound on the size or number of objects in PDFs it processes, rejecting files that exceed the defined threshold.
  • Implement monitoring of memory and CPU usage for processes that use pypdf, and trigger alerts or automatic restarts when usage climbs beyond normal limits.

Generated by OpenCVE AI on September 30, 2026 at 22:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-606
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Wed, 30 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description pypdf is a free and open-source pure-python PDF library. Prior to 6.18.0, a crafted PDF containing indirect-object identifiers or generation-number tokens that continue for a long time without whitespace can cause pypdf/_reader.py and pypdf/generic/_base.py to scan excessive input through read_until_whitespace, resulting in long runtimes and application unavailability. This issue is fixed in version 6.18.0.
Title pypdf: Possible long runtimes/large memory usage when parsing indirect objects
Weaknesses CWE-400
CWE-407
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-30T20:50:16.366Z

Reserved: 2026-09-29T20:46:08.334Z

Link: CVE-2026-102994

cve-icon Vulnrichment

Updated: 2026-09-30T20:50:12.372Z

cve-icon NVD

Status : Received

Published: 2026-09-30T20:17:28.080

Modified: 2026-09-30T21:17:06.587

Link: CVE-2026-102994

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-30T19:57:37Z

Links: CVE-2026-102994 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T22:45:16Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-407

    Inefficient Algorithmic Complexity

  • CWE-606

    Unchecked Input for Loop Condition