Excessive Resource Consumption in pypdf Library by PyPDF Team
CVE-2026-102998

8.7HIGH

Key Information:

Vendor

Py-PDF

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-102998?

The pypdf library, an open-source PDF manipulation tool, is vulnerable to issues caused by carefully crafted PDFs with form field values. In versions prior to 6.19.0, an exploit can occur during the generation of appearance streams for form fields with flattening enabled, causing repetitive processing within a loop. This results in excessive resource consumption, leading to application unavailability. It is strongly recommended to update to version 6.19.0 or later to mitigate this issue.

Affected Version(s)

pypdf < 6.19.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.