Impact
A crafted PDF that contains complex form field values triggers a loop in pypdf’s appearance‑stream generation routine when fields are updated with flattening enabled, causing extremely long runtimes. The library repeatedly processes invariant selection data, which can consume significant CPU resources and effectively render the application unresponsive. This leads to a denial‑of‑service condition affecting availability.
Affected Systems
The vulnerability affects the py‑pdf:pypdf library, a pure‑Python PDF manipulation package used in many Python applications. Any deployment using pypdf versions earlier than 6.19.0 is susceptible; the issue was addressed in the 6.19.0 release. Systems that load or process PDFs with form fields and enable the flattening option during field updates are at risk.
Risk and Exploitability
The CVSS score of 8.7 classifies this flaw as high severity. Because no EPSS data is available and the vulnerability is not listed in the CISA KEV catalog, a precise exploitation probability cannot be quantified, but the presence of an easily reproducible loop indicates that an attacker who can supply a malicious PDF file or otherwise force the application to process specific input could trigger the DoS. The likely attack vector is local or remote file ingestion; the application must accept user‑supplied PDFs or be exposed to a network interface that processes PDFs, which creates a potential entry point.
OpenCVE Enrichment