Inefficient Byte-by-Byte Decompression in pypdf Library
CVE-2026-102997

8.7HIGH

Key Information:

Vendor

Py-PDF

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-102997?

The pypdf library is susceptible to a vulnerability arising from a crafted PDF that contains a malformed /FlateDecode stream with padded data. This issue causes the library to resort to inefficient byte-by-byte decompression, resulting in significantly long runtimes and potential application unavailability. Despite previous fixes for FlateDecode recovery mechanisms, this residual issue persists until version 6.18.1, necessitating an important update for users to maintain system performance and availability.

Affected Version(s)

pypdf < 6.18.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.