Description
pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF containing many embedded files can cause the dictionary-based attachments API in pypdf/_doc_common.py to reparse the full attachment list for each content lookup, producing repeated work and long runtimes when an application accesses the embedded-file mapping. This issue is fixed in version 6.19.0.
Published: 2026-09-30
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

A crafted PDF containing many embedded files can cause the pypdf dictionary‑based attachments API to reparse the full attachment list for each content lookup. This results in repeated processing and significantly increased runtimes, potentially exhausting system resources and causing a denial of service when an application accesses the embedded‑file mapping. The flaw is caused by uncontrolled resource consumption and is catalogued as CWE-400 and CWE-407. The issue has been mitigated in pypdf version 6.19.0.

Affected Systems

The vulnerability affects the pypdf library (py‑pdf:pypdf) versions released prior to 6.19.0. Any project or service that imports and parses PDFs using older releases of this library is potentially impacted.

Risk and Exploitability

With a high CVSS score of 8.7 and no EPSS data available, the exploitation likelihood is uncertain, but the potential impact is significant. The attack vector is inferred to involve an attacker supplying a malicious PDF to an application that uses pypdf for parsing; this could lead to prolonged execution times or resource starvation. The vulnerability is not currently listed in the CISA KEV catalog, suggesting no publicly documented exploits yet, but the severity and the widespread use of pypdf warrant prompt attention.

Generated by OpenCVE AI on September 30, 2026 at 22:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the pypdf library to version 6.19.0 or later.
  • Before parsing, validate incoming PDFs to ensure they do not contain an excessive number of embedded files and reject those that exceed reasonable limits.
  • Configure application‑level CPU and memory limits around PDF processing to mitigate potential denial of service attacks.

Generated by OpenCVE AI on September 30, 2026 at 22:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-606
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF containing many embedded files can cause the dictionary-based attachments API in pypdf/_doc_common.py to reparse the full attachment list for each content lookup, producing repeated work and long runtimes when an application accesses the embedded-file mapping. This issue is fixed in version 6.19.0.
Title pypdf: Possible long runtimes with large amount of embedded files
Weaknesses CWE-400
CWE-407
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-30T20:10:38.433Z

Reserved: 2026-09-29T20:46:08.335Z

Link: CVE-2026-102999

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T21:17:07.343

Modified: 2026-09-30T21:17:07.343

Link: CVE-2026-102999

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-30T20:10:38Z

Links: CVE-2026-102999 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T22:30:07Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-407

    Inefficient Algorithmic Complexity

  • CWE-606

    Unchecked Input for Loop Condition