Description
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtimes when the pypdf/_utils.py function read_until_whitespace reads a stream containing a long run of bytes without whitespace. The function repeatedly performs immutable bytes concatenation in a one-byte loop, causing quadratic processing cost for the long non-whitespace input. This issue is fixed in version 6.15.0.
Published: 2026-08-31
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the function read_until_whitespace within pypdf/_utils.py causes each byte of a stream to be concatenated into a new immutable bytes object one at a time. For a stream that contains a long run of non‑whitespace bytes, the routine performs a quadratic number of concatenations, leading to very high CPU usage and prolonged runtimes. The weakness is categorized as CWE‑407 (Improper Resource Allocation).

Affected Systems

The issue affects all versions of py-pdf:pypdf released before 6.15.0. Any application that imports and uses pypdf to process PDF files is potentially impacted.

Risk and Exploitability

The vulnerability is scored CVSS 6.9, indicating moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a crafted PDF file supplied to an application using pypdf; upon parsing a stream with a long non‑whitespace sequence, the application will experience high CPU load and may become unresponsive. No network‑side or privilege escalation component is described in the information provided.

Generated by OpenCVE AI on August 31, 2026 at 22:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade py‑pdf:pypdf to version 6.15.0 or later.
  • Implement input validation to detect and reject PDFs containing unusually long non‑whitespace byte sequences before they reach pypdf.
  • Monitor CPU usage during PDF processing and alert on sudden spikes that may indicate exploitation attempts.

Generated by OpenCVE AI on August 31, 2026 at 22:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Py-pdf
Py-pdf pypdf
Vendors & Products Py-pdf
Py-pdf pypdf

Mon, 31 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtimes when the pypdf/_utils.py function read_until_whitespace reads a stream containing a long run of bytes without whitespace. The function repeatedly performs immutable bytes concatenation in a one-byte loop, causing quadratic processing cost for the long non-whitespace input. This issue is fixed in version 6.15.0.
Title pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace
Weaknesses CWE-407
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-31T21:41:10.272Z

Reserved: 2026-08-28T22:00:43.512Z

Link: CVE-2026-82398

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T22:17:23.083

Modified: 2026-08-31T22:17:23.083

Link: CVE-2026-82398

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T23:30:06Z

Weaknesses
  • CWE-407

    Inefficient Algorithmic Complexity