
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-102999 is a denial-of-service vulnerability in pypdf, a free and open-source pure-Python PDF library, caused by inefficient algorithmic complexity in the dictionary-based attachments API. A crafted PDF containing a large number of embedded files can cause the attachments property in pypdf/_doc_common.py to reparse the full attachment list for every content lookup, resulting in excessive CPU consumption and long runtimes. All versions of pypdf prior to 6.19.0 are affected. The vulnerability was disclosed on September 30, 2026, with a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Red Hat CVE).
The root cause is an inefficient O(n²) lookup pattern (CWE-407: Inefficient Algorithmic Complexity; CWE-400: Uncontrolled Resource Consumption; CWE-606: Unchecked Input for Loop Condition) in the attachments property of pypdf/_doc_common.py. In the vulnerable implementation, iterating over the attachment mapping via .items() caused each content retrieval to invoke _get_attachment_list(), which in turn called _get_attachments() — reparsing the entire embedded-file list from scratch for every lookup. An attacker can exploit this by supplying a crafted PDF with a large number of embedded files to any application that accesses the attachments dictionary-based API, triggering repeated full list traversals. The fix, introduced in PR #4081, restructures the logic to record associated file objects per name during a single traversal, making subsequent content retrieval a direct stream access operation (GitHub Advisory, GitHub PR #4081, Fix Commit).
Successful exploitation causes the affected application to consume excessive CPU resources and experience significant performance degradation or complete unresponsiveness when processing the malicious PDF. The impact is limited to availability — there is no confidentiality or integrity impact, and no lateral movement or data exfiltration risk is associated with this vulnerability. Any service that accepts user-supplied PDF files and accesses the embedded-file mapping (e.g., document management systems, email gateways, or web applications using pypdf) is at risk of denial of service (GitHub Advisory, Red Hat CVE).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time. The vulnerability requires no authentication, no privileges, and no user interaction — an attacker simply needs to supply a crafted PDF to an application that processes embedded-file mappings via pypdf. The EPSS score is 0.0, reflecting low current exploitation probability, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Red Hat CVE).
attachments dictionary-based API (e.g., iterates over pdf.attachments.items()).Upgrade pypdf to version 6.19.0 or later, which resolves the issue by restructuring the attachment mapping to perform a single traversal and cache file object references (pypdf Release 6.19.0). For deployments that cannot upgrade immediately, the maintainers recommend manually applying the changes from PR #4081 as a workaround (GitHub PR #4081). Additionally, consider implementing input validation to reject PDFs with an excessive number of embedded files, and monitor applications for unusual CPU consumption during PDF processing.
The vulnerability was reported by researcher jungmingi-lab and addressed by pypdf maintainer stefan6419846, who merged the fix on September 14, 2026, ahead of the public disclosure on September 30, 2026 (GitHub Advisory). No significant broader media coverage or notable community commentary beyond the GitHub advisory and standard CVE tracking databases has been observed.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."