Impact
A crafted PDF containing many embedded files can cause the pypdf dictionary‑based attachments API to reparse the full attachment list for each content lookup. This results in repeated processing and significantly increased runtimes, potentially exhausting system resources and causing a denial of service when an application accesses the embedded‑file mapping. The flaw is caused by uncontrolled resource consumption and is catalogued as CWE-400 and CWE-407. The issue has been mitigated in pypdf version 6.19.0.
Affected Systems
The vulnerability affects the pypdf library (py‑pdf:pypdf) versions released prior to 6.19.0. Any project or service that imports and parses PDFs using older releases of this library is potentially impacted.
Risk and Exploitability
With a high CVSS score of 8.7 and no EPSS data available, the exploitation likelihood is uncertain, but the potential impact is significant. The attack vector is inferred to involve an attacker supplying a malicious PDF to an application that uses pypdf for parsing; this could lead to prolonged execution times or resource starvation. The vulnerability is not currently listed in the CISA KEV catalog, suggesting no publicly documented exploits yet, but the severity and the widespread use of pypdf warrant prompt attention.
OpenCVE Enrichment