Description
pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF with form field values can cause pypdf/generic/_appearance_stream.py appearance-stream generation to repeat invariant selection-data work inside a loop when an application updates fields with flattening enabled, resulting in excessive runtimes and application unavailability. This issue is fixed in version 6.19.0.
Published: 2026-09-30
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Denial of Service (excessive runtimes)
Action: Update Library
AI Analysis

Impact

A crafted PDF that contains complex form field values triggers a loop in pypdf’s appearance‑stream generation routine when fields are updated with flattening enabled, causing extremely long runtimes. The library repeatedly processes invariant selection data, which can consume significant CPU resources and effectively render the application unresponsive. This leads to a denial‑of‑service condition affecting availability.

Affected Systems

The vulnerability affects the py‑pdf:pypdf library, a pure‑Python PDF manipulation package used in many Python applications. Any deployment using pypdf versions earlier than 6.19.0 is susceptible; the issue was addressed in the 6.19.0 release. Systems that load or process PDFs with form fields and enable the flattening option during field updates are at risk.

Risk and Exploitability

The CVSS score of 8.7 classifies this flaw as high severity. Because no EPSS data is available and the vulnerability is not listed in the CISA KEV catalog, a precise exploitation probability cannot be quantified, but the presence of an easily reproducible loop indicates that an attacker who can supply a malicious PDF file or otherwise force the application to process specific input could trigger the DoS. The likely attack vector is local or remote file ingestion; the application must accept user‑supplied PDFs or be exposed to a network interface that processes PDFs, which creates a potential entry point.

Generated by OpenCVE AI on September 30, 2026 at 22:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade pypdf to version 6.19.0 or later to eliminate the loop causing excessive runtimes.
  • If an immediate upgrade is not possible, disable the flattening feature or otherwise prevent the library from regenerating appearance streams for user‑supplied PDFs.
  • Validate or sanitize PDF input prior to processing and limit the number of form fields or complexity allowed.
  • Monitor application performance for abnormal CPU usage and implement runtime limits or process isolation when handling PDFs.

Generated by OpenCVE AI on September 30, 2026 at 22:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-606
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Wed, 30 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF with form field values can cause pypdf/generic/_appearance_stream.py appearance-stream generation to repeat invariant selection-data work inside a loop when an application updates fields with flattening enabled, resulting in excessive runtimes and application unavailability. This issue is fixed in version 6.19.0.
Title pypdf: Possible long runtimes when generating appearance streams
Weaknesses CWE-400
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-30T20:49:30.419Z

Reserved: 2026-09-29T20:46:08.335Z

Link: CVE-2026-102998

cve-icon Vulnrichment

Updated: 2026-09-30T20:49:27.400Z

cve-icon NVD

Status : Received

Published: 2026-09-30T21:17:07.177

Modified: 2026-09-30T21:17:07.177

Link: CVE-2026-102998

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-30T20:09:13Z

Links: CVE-2026-102998 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T22:45:16Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-606

    Unchecked Input for Loop Condition