Description
pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF containing a partially malformed /FlateDecode stream with padded data can force pypdf/filters.py to use inefficient byte-by-byte decompression while the earlier recovery counter fails to advance for bytes that successfully decode, causing long runtimes and application unavailability. This is a residual issue after the malformed FlateDecode recovery fix. This issue is fixed in version 6.18.1.
Published: 2026-09-30
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability involves a partially malformed /FlateDecode stream containing padded data. When processed by pypdf/filters.py the library falls back to a byte‑by‑byte decompression loop and the recovery counter does not advance for successfully decoded bytes, leading to extremely long runtimes and eventual application unavailability. This constitutes a denial‑of‑service condition caused by resource exhaustion and inefficient algorithm use.

Affected Systems

The issue affects the py‑pdf:pypdf library in all releases before version 6.18.1. Any application that imports pypdf and parses user supplied PDFs is potentially impacted, including automating PDF generation or conversion tasks. Version 6.18.1 and later contain the fix.

Risk and Exploitability

The CVSS score of 8.7 rates the flaw as high severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting it may not yet be actively exploited. The attack is possible if an adversary can supply a crafted PDF to a target system that uses pypdf; the exploitation requires no special privileges beyond the ability to deliver the PDF to the application. Successful exploitation can lead to prolonged processing times or hang the service. The risk is elevated in environments that trust external PDFs or expose PDF handling over a network.

Generated by OpenCVE AI on September 30, 2026 at 22:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the pypdf Python library to version 6.18.1 or newer, which contains the deflation stream bug fix.
  • Implement a processing timeout or watchdog around pypdf calls to limit execution time and prevent hangs caused by malformed streams.
  • Validate incoming PDF files against the pypdf library’s schema or remove the /FlateDecode filter before parsing when possible, to reduce the attack surface.

Generated by OpenCVE AI on September 30, 2026 at 22:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-835
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF containing a partially malformed /FlateDecode stream with padded data can force pypdf/filters.py to use inefficient byte-by-byte decompression while the earlier recovery counter fails to advance for bytes that successfully decode, causing long runtimes and application unavailability. This is a residual issue after the malformed FlateDecode recovery fix. This issue is fixed in version 6.18.1.
Title pypdf: Possible long runtimes for partially malformed FlateDecode streams (Follow-up)
Weaknesses CWE-400
CWE-407
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-30T20:05:51.538Z

Reserved: 2026-09-29T20:46:08.335Z

Link: CVE-2026-102997

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T21:17:07.020

Modified: 2026-09-30T21:17:07.020

Link: CVE-2026-102997

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-30T20:05:51Z

Links: CVE-2026-102997 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T22:45:16Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-407

    Inefficient Algorithmic Complexity

  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')