Vulnerability DatabaseCVE-2026-102998

CVE-2026-102998: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-102998 is a Denial of Service vulnerability in pypdf, a free and open-source pure-Python PDF library. Prior to version 6.19.0, a crafted PDF with form field values can cause the appearance-stream generation code in pypdf/generic/_appearance_stream.py to repeat invariant selection-data work inside a loop when an application updates fields with flattening enabled, resulting in excessive CPU consumption and application unavailability. The vulnerability was disclosed on September 30, 2026, and affects all pypdf versions before 6.19.0. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Red Hat).

Technical details

The root cause is classified as CWE-400 (Uncontrolled Resource Consumption) and CWE-606 (Unchecked Input for Loop Condition). In the vulnerable code path within pypdf/generic/_appearance_stream.py, the function _unicode_to_glyph_id() was called repeatedly inside a loop for each line of text, even though the result (derived from the selection parameter) is invariant across iterations. A crafted PDF with specially constructed form field values — particularly choice fields with large numbers of options and selected values — triggers this inefficient code path when update_page_form_field_values() is called with flatten=True, causing quadratic or worse runtime behavior. The fix, implemented in PR #4087, moves the _unicode_to_glyph_id() call outside the loop so it is computed only once (GitHub PR #4087, GitHub Commit).

Impact

Successful exploitation causes excessive CPU consumption in the affected application, leading to application unavailability (Denial of Service) for legitimate users. There is no impact on confidentiality or data integrity — the vulnerability is purely an availability issue. Any application that accepts PDF uploads and processes form fields with flattening enabled is at risk, and an unauthenticated remote attacker can trigger the condition by submitting a single crafted PDF file (GitHub Advisory, Red Hat Bugzilla).

Exploitability

No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time. The vulnerability is rated automatable (no user interaction required, no privileges needed, network-accessible), making it straightforward to trigger remotely against any exposed application that processes PDFs with field flattening. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (GitHub Advisory, Red Hat).

Exploitation steps

  1. Identify a target application: Locate a web application or service that accepts PDF file uploads and uses pypdf (version < 6.19.0) to process form fields with flatten=True (e.g., PDF form processing services, document management systems).
  2. Craft a malicious PDF: Create a PDF containing an AcroForm choice field (/FT /Ch) with a large number of options (/Opt) and a large number of selected values (/V) — for example, 1,000 options and 1,000 selected values, as demonstrated in the test case added with the fix.
  3. Submit the crafted PDF: Upload or submit the malicious PDF to the target application via its normal file upload interface.
  4. Trigger field flattening: The application calls update_page_form_field_values() with flatten=True, which invokes the vulnerable appearance-stream generation code in _appearance_stream.py.
  5. Achieve Denial of Service: The _unicode_to_glyph_id() function is called repeatedly inside the loop for each line, causing excessive CPU consumption that hangs or crashes the application process, making it unavailable to legitimate users (GitHub PR #4087, GitHub Advisory).

Indicators of compromise

  • Network: Repeated PDF upload requests from the same source IP, particularly with unusually large or structurally complex PDF files targeting form-processing endpoints.
  • Process: The Python process running pypdf exhibiting sustained high CPU usage (near 100%) for extended periods when processing a single PDF file; application worker timeouts or process hangs following a PDF upload.
  • Logs: Application logs showing timeouts, worker process restarts, or unresponsive state immediately after a PDF form-processing operation; log entries referencing pypdf/generic/_appearance_stream.py in stack traces if exceptions are raised.
  • File System: Presence of crafted PDF files with AcroForm choice fields containing abnormally large /Opt or /V arrays (hundreds to thousands of entries) in upload directories.

Mitigation and workarounds

The primary remediation is to upgrade pypdf to version 6.19.0 or later, which contains the fix released on September 16, 2026 (pypdf Release 6.19.0). For deployments that cannot upgrade immediately, the maintainers recommend manually applying the changes from PR #4087, which moves the invariant _unicode_to_glyph_id() call outside the loop in _appearance_stream.py (GitHub PR #4087). As an additional workaround, applications can implement input validation to restrict PDF uploads (e.g., file size limits, field count limits) or disable field flattening functionality when processing untrusted PDF files.

Community reactions

The vulnerability was reported by researcher manop55555 and addressed by pypdf maintainer stefan6419846, who noted the issue could be triggered with a field value of None (outside normal type hint constraints) but that the fix is beneficial for all cases (GitHub PR #4087). Red Hat tracked the issue as high severity in their Bugzilla system, with 24 users CC'd on the bug report, indicating broad interest across Red Hat product lines (Red Hat Bugzilla). No significant broader media coverage or social media discussion has been identified at this time.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

pypdf2

Affected

sid

pypdf: 6.19.0-1

Fixed

trixie

pypdf

Affected

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
GHSA-jqmf-mx4f-hfr6CRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
GHSA-8mcx-5rqc-vhmfHIGH8.8
  • Python logoPython
  • dulwich
NoYesOct 02, 2026
GHSA-5rmq-chc7-m22fHIGH7.5
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
GHSA-35mr-4567-66vgMEDIUM6.5
  • Python logoPython
  • dulwich
NoYesOct 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management