Impact
pypdf, a pure‑Python PDF library, can be made to spend an excessive amount of time and memory parsing a PDF that contains unusually long indirect‑object identifiers or generation‑number tokens without intervening whitespace. The library’s read_until_whitespace routine then scans a large chunk of input, which can lead to prolonged execution times and application unavailability. The flaw represents uncontrolled resource consumption ( unexplained resource exhaustion (CWE‑407).
Affected Systems
The vulnerability affects the py‑pdf:pypdf library in all releases older than 6.18.0. Any Python application that imports pypdf to read, merge, or otherwise process PDFs could be impacted when it receives a specially crafted document.
Risk and Exploitability
With a CVSS score of 8.7 the issue is considered high severity. No EPSS value is available and it is not listed in the CISA KEV catalog. Attackers can supply a malicious PDF to an application using pypdf; the library will then consume significant CPU and memory, potentially exhausting system resources and causing a denial of service. The attack vector is local or remote depending on how the application receives PDF content. No immediate code‑execution vector exists, but the resource exhaustion can degrade availability for legitimate users.
OpenCVE Enrichment