Inefficient Byte-by-Byte Decompression in pypdf Library
CVE-2026-102997
8.7HIGH
What is CVE-2026-102997?
The pypdf library is susceptible to a vulnerability arising from a crafted PDF that contains a malformed /FlateDecode stream with padded data. This issue causes the library to resort to inefficient byte-by-byte decompression, resulting in significantly long runtimes and potential application unavailability. Despite previous fixes for FlateDecode recovery mechanisms, this residual issue persists until version 6.18.1, necessitating an important update for users to maintain system performance and availability.
Affected Version(s)
pypdf < 6.18.1
