Excessive Input Handling Vulnerability in pypdf Product from PyPDF
CVE-2026-102994

8.7HIGH

Key Information:

Vendor

Py-PDF

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-102994?

A vulnerability exists in the pypdf library, which is a widely used free and open-source pure-Python PDF library. Versions before 6.18.0 are susceptible to excessive input processing when handling crafted PDF files. These files may contain indirect-object identifiers or prolonged generation-number tokens without whitespace, leading the application to execute lengthy scans through specific reading functions. This can result in significant delays or even complete application unavailability. Users are encouraged to update to version 6.18.0 to mitigate this issue.

Affected Version(s)

pypdf < 6.18.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.