Vulnerability DatabaseCVE-2026-102999

CVE-2026-102999: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-102999 is a denial-of-service vulnerability in pypdf, a free and open-source pure-Python PDF library, caused by inefficient algorithmic complexity in the dictionary-based attachments API. A crafted PDF containing a large number of embedded files can cause the attachments property in pypdf/_doc_common.py to reparse the full attachment list for every content lookup, resulting in excessive CPU consumption and long runtimes. All versions of pypdf prior to 6.19.0 are affected. The vulnerability was disclosed on September 30, 2026, with a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Red Hat CVE).

Technical details

The root cause is an inefficient O(n²) lookup pattern (CWE-407: Inefficient Algorithmic Complexity; CWE-400: Uncontrolled Resource Consumption; CWE-606: Unchecked Input for Loop Condition) in the attachments property of pypdf/_doc_common.py. In the vulnerable implementation, iterating over the attachment mapping via .items() caused each content retrieval to invoke _get_attachment_list(), which in turn called _get_attachments() — reparsing the entire embedded-file list from scratch for every lookup. An attacker can exploit this by supplying a crafted PDF with a large number of embedded files to any application that accesses the attachments dictionary-based API, triggering repeated full list traversals. The fix, introduced in PR #4081, restructures the logic to record associated file objects per name during a single traversal, making subsequent content retrieval a direct stream access operation (GitHub Advisory, GitHub PR #4081, Fix Commit).

Impact

Successful exploitation causes the affected application to consume excessive CPU resources and experience significant performance degradation or complete unresponsiveness when processing the malicious PDF. The impact is limited to availability — there is no confidentiality or integrity impact, and no lateral movement or data exfiltration risk is associated with this vulnerability. Any service that accepts user-supplied PDF files and accesses the embedded-file mapping (e.g., document management systems, email gateways, or web applications using pypdf) is at risk of denial of service (GitHub Advisory, Red Hat CVE).

Exploitability

No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time. The vulnerability requires no authentication, no privileges, and no user interaction — an attacker simply needs to supply a crafted PDF to an application that processes embedded-file mappings via pypdf. The EPSS score is 0.0, reflecting low current exploitation probability, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Red Hat CVE).

Exploitation steps

  1. Craft a malicious PDF: Create a PDF document containing a very large number of embedded files (attachments). Each additional embedded file increases the computational cost of each subsequent attachment lookup, amplifying the denial-of-service effect.
  2. Identify a target application: Locate a service or application that accepts user-supplied PDF files and processes them using pypdf (versions < 6.19.0), specifically one that accesses the attachments dictionary-based API (e.g., iterates over pdf.attachments.items()).
  3. Submit the crafted PDF: Upload or send the malicious PDF to the target application through any available input channel (file upload form, email attachment, API endpoint, etc.).
  4. Trigger the vulnerable code path: The application accesses the embedded-file mapping, causing pypdf to reparse the full attachment list for each content lookup — resulting in O(n²) work, excessive CPU consumption, and prolonged or indefinite processing time, effectively denying service to legitimate users (GitHub Advisory, GitHub PR #4081).

Indicators of compromise

  • Process: Sustained high CPU usage by the Python process handling PDF parsing, particularly when processing a single PDF file with many embedded attachments.
  • Logs: Application logs showing unusually long processing times or timeouts when handling specific PDF files; repeated invocations of attachment-related code paths.
  • File System: Presence of suspicious PDF files with an abnormally large number of embedded file entries in upload directories or temporary processing folders.
  • Network: Repeated submission of the same or similar large PDF files from a single source IP to a PDF-processing endpoint.

Mitigation and workarounds

Upgrade pypdf to version 6.19.0 or later, which resolves the issue by restructuring the attachment mapping to perform a single traversal and cache file object references (pypdf Release 6.19.0). For deployments that cannot upgrade immediately, the maintainers recommend manually applying the changes from PR #4081 as a workaround (GitHub PR #4081). Additionally, consider implementing input validation to reject PDFs with an excessive number of embedded files, and monitor applications for unusual CPU consumption during PDF processing.

Community reactions

The vulnerability was reported by researcher jungmingi-lab and addressed by pypdf maintainer stefan6419846, who merged the fix on September 14, 2026, ahead of the public disclosure on September 30, 2026 (GitHub Advisory). No significant broader media coverage or notable community commentary beyond the GitHub advisory and standard CVE tracking databases has been observed.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

pypdf2

Affected

sid

pypdf: 6.19.0-1

Fixed

trixie

pypdf

Affected

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
GHSA-jqmf-mx4f-hfr6CRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
GHSA-8mcx-5rqc-vhmfHIGH8.8
  • Python logoPython
  • dulwich
NoYesOct 02, 2026
GHSA-5rmq-chc7-m22fHIGH7.5
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
GHSA-35mr-4567-66vgMEDIUM6.5
  • Python logoPython
  • dulwich
NoYesOct 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management