
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-102998 is a Denial of Service vulnerability in pypdf, a free and open-source pure-Python PDF library. Prior to version 6.19.0, a crafted PDF with form field values can cause the appearance-stream generation code in pypdf/generic/_appearance_stream.py to repeat invariant selection-data work inside a loop when an application updates fields with flattening enabled, resulting in excessive CPU consumption and application unavailability. The vulnerability was disclosed on September 30, 2026, and affects all pypdf versions before 6.19.0. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Red Hat).
The root cause is classified as CWE-400 (Uncontrolled Resource Consumption) and CWE-606 (Unchecked Input for Loop Condition). In the vulnerable code path within pypdf/generic/_appearance_stream.py, the function _unicode_to_glyph_id() was called repeatedly inside a loop for each line of text, even though the result (derived from the selection parameter) is invariant across iterations. A crafted PDF with specially constructed form field values — particularly choice fields with large numbers of options and selected values — triggers this inefficient code path when update_page_form_field_values() is called with flatten=True, causing quadratic or worse runtime behavior. The fix, implemented in PR #4087, moves the _unicode_to_glyph_id() call outside the loop so it is computed only once (GitHub PR #4087, GitHub Commit).
Successful exploitation causes excessive CPU consumption in the affected application, leading to application unavailability (Denial of Service) for legitimate users. There is no impact on confidentiality or data integrity — the vulnerability is purely an availability issue. Any application that accepts PDF uploads and processes form fields with flattening enabled is at risk, and an unauthenticated remote attacker can trigger the condition by submitting a single crafted PDF file (GitHub Advisory, Red Hat Bugzilla).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time. The vulnerability is rated automatable (no user interaction required, no privileges needed, network-accessible), making it straightforward to trigger remotely against any exposed application that processes PDFs with field flattening. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (GitHub Advisory, Red Hat).
flatten=True (e.g., PDF form processing services, document management systems)./FT /Ch) with a large number of options (/Opt) and a large number of selected values (/V) — for example, 1,000 options and 1,000 selected values, as demonstrated in the test case added with the fix.update_page_form_field_values() with flatten=True, which invokes the vulnerable appearance-stream generation code in _appearance_stream.py._unicode_to_glyph_id() function is called repeatedly inside the loop for each line, causing excessive CPU consumption that hangs or crashes the application process, making it unavailable to legitimate users (GitHub PR #4087, GitHub Advisory).pypdf/generic/_appearance_stream.py in stack traces if exceptions are raised./Opt or /V arrays (hundreds to thousands of entries) in upload directories.The primary remediation is to upgrade pypdf to version 6.19.0 or later, which contains the fix released on September 16, 2026 (pypdf Release 6.19.0). For deployments that cannot upgrade immediately, the maintainers recommend manually applying the changes from PR #4087, which moves the invariant _unicode_to_glyph_id() call outside the loop in _appearance_stream.py (GitHub PR #4087). As an additional workaround, applications can implement input validation to restrict PDF uploads (e.g., file size limits, field count limits) or disable field flattening functionality when processing untrusted PDF files.
The vulnerability was reported by researcher manop55555 and addressed by pypdf maintainer stefan6419846, who noted the issue could be triggered with a field value of None (outside normal type hint constraints) but that the fix is beneficial for all cases (GitHub PR #4087). Red Hat tracked the issue as high severity in their Bugzilla system, with 24 users CC'd on the bug report, indicating broad interest across Red Hat product lines (Red Hat Bugzilla). No significant broader media coverage or social media discussion has been identified at this time.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."