CVE-2026-102997: CWE-400: Uncontrolled Resource Consumption in py-pdf pypdf
CVE-2026-102997 is a high-severity vulnerability in the pypdf library prior to version 6.18.1. It involves uncontrolled resource consumption caused by a crafted PDF with a malformed /FlateDecode stream that triggers inefficient byte-by-byte decompression. This leads to long runtimes and potential application unavailability. The issue is a residual problem after a previous fix related to malformed FlateDecode recovery. The vulnerability is fixed in pypdf version 6.18.1.
AI Analysis
Technical Summary
The vulnerability in pypdf (CVE-2026-102997) arises when processing a crafted PDF containing a partially malformed /FlateDecode stream with padded data. This causes the decompression logic in pypdf/filters.py to fall back to inefficient byte-by-byte decompression. Additionally, the recovery counter used to handle malformed data does not advance correctly for bytes that decode successfully, resulting in prolonged processing times and potential denial of service due to application unavailability. This issue persists as a residual flaw after an earlier fix addressing malformed FlateDecode streams. The vulnerability is resolved in version 6.18.1 of pypdf.
Potential Impact
An attacker can craft a specially malformed PDF that triggers inefficient decompression in pypdf, causing excessive CPU usage and long runtimes. This can lead to denial of service by making the application using pypdf unavailable or unresponsive during processing of such PDFs.
Mitigation Recommendations
Upgrade to pypdf version 6.18.1 or later, where this vulnerability is fixed. No additional mitigation is required once the update is applied.
CVE-2026-102997: CWE-400: Uncontrolled Resource Consumption in py-pdf pypdf
Description
CVE-2026-102997 is a high-severity vulnerability in the pypdf library prior to version 6.18.1. It involves uncontrolled resource consumption caused by a crafted PDF with a malformed /FlateDecode stream that triggers inefficient byte-by-byte decompression. This leads to long runtimes and potential application unavailability. The issue is a residual problem after a previous fix related to malformed FlateDecode recovery. The vulnerability is fixed in pypdf version 6.18.1.
CVSS v4.0
Score 8.7high
Affected software
py-pdf
pypdf
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in pypdf (CVE-2026-102997) arises when processing a crafted PDF containing a partially malformed /FlateDecode stream with padded data. This causes the decompression logic in pypdf/filters.py to fall back to inefficient byte-by-byte decompression. Additionally, the recovery counter used to handle malformed data does not advance correctly for bytes that decode successfully, resulting in prolonged processing times and potential denial of service due to application unavailability. This issue persists as a residual flaw after an earlier fix addressing malformed FlateDecode streams. The vulnerability is resolved in version 6.18.1 of pypdf.
Potential Impact
An attacker can craft a specially malformed PDF that triggers inefficient decompression in pypdf, causing excessive CPU usage and long runtimes. This can lead to denial of service by making the application using pypdf unavailable or unresponsive during processing of such PDFs.
Mitigation Recommendations
Upgrade to pypdf version 6.18.1 or later, where this vulnerability is fixed. No additional mitigation is required once the update is applied.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-09-29T20:46:08.335Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abd72532a4e24523d8ec0e3
Added to database: 09/30/2026, 20:34:27 UTC
Last enriched: 09/30/2026, 20:48:11 UTC
Last updated: 10/01/2026, 04:54:03 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.