Performance Degradation in pypdf Due to Embedded PDF File Handling
CVE-2026-102999

8.7HIGH

Key Information:

Vendor

Py-PDF

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-102999?

A performance issue has been identified in the pypdf library prior to version 6.19.0. This vulnerability occurs when a specially crafted PDF containing numerous embedded files triggers excessive reprocessing within the dictionary-based attachments API. Specifically, the full attachment list is reparsed for each content lookup, leading to prolonged runtimes during PDF access and inefficient resource utilization. Users of this library are encouraged to upgrade to version 6.19.0 to mitigate this impact and enhance performance.

Affected Version(s)

pypdf < 6.19.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.