Impact
The vulnerability involves a partially malformed /FlateDecode stream containing padded data. When processed by pypdf/filters.py the library falls back to a byte‑by‑byte decompression loop and the recovery counter does not advance for successfully decoded bytes, leading to extremely long runtimes and eventual application unavailability. This constitutes a denial‑of‑service condition caused by resource exhaustion and inefficient algorithm use.
Affected Systems
The issue affects the py‑pdf:pypdf library in all releases before version 6.18.1. Any application that imports pypdf and parses user supplied PDFs is potentially impacted, including automating PDF generation or conversion tasks. Version 6.18.1 and later contain the fix.
Risk and Exploitability
The CVSS score of 8.7 rates the flaw as high severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting it may not yet be actively exploited. The attack is possible if an adversary can supply a crafted PDF to a target system that uses pypdf; the exploitation requires no special privileges beyond the ability to deliver the PDF to the application. Successful exploitation can lead to prolonged processing times or hang the service. The risk is elevated in environments that trust external PDFs or expose PDF handling over a network.
OpenCVE Enrichment