{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3apy-pdfpypdf/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:py-pdf:pypdf:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-102999"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["pypdf (\u003c 6.19.0)","pypdf (\u003c 6.18.1)","pypdf (\u003c 6.18.0)"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","dos","denial-of-service","library-vulnerability","python"],"_cs_type":"advisory","_cs_vendors":["py-pdf","pypdf"],"content_html":"\u003cp\u003eThe pypdf library is susceptible to a denial-of-service condition identified as CVE-2026-102999. This vulnerability stems from inefficient handling of embedded files within PDF documents. When an application uses the library's dictionary-based API to access embedded files, a specially crafted PDF containing a large number of these objects can trigger a performance degradation, resulting in excessively long runtimes and potential service exhaustion. This issue affects all versions of pypdf prior to 6.19.0. Organizations processing untrusted or user-supplied PDF documents using this library are at risk of resource depletion attacks targeting their document processing pipelines.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a denial-of-service condition where the application becomes unresponsive due to the excessive computational load required to process the malicious PDF. This impacts any system or automated service that parses, extracts, or inspects embedded content from PDF files using affected versions of pypdf.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for development and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the pypdf dependency to version 6.19.0 or later to include the fix for CVE-2026-102999.\u003c/li\u003e\n\u003cli\u003eIf upgrading is not immediately feasible, apply the patches provided in PR #4081 to mitigate the excessive runtime behavior.\u003c/li\u003e\n\u003cli\u003eImplement resource limits, such as execution timeouts or CPU usage quotas, for processes that invoke pypdf on untrusted input files.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T20:23:31Z","date_published":"2026-10-01T20:22:57Z","id":"https://feed.craftedsignal.io/briefs/2026-10-pypdf-dos/","summary":"The pypdf library contains a vulnerability, CVE-2026-102999, that allows an attacker to cause excessive execution times by providing a crafted PDF with numerous embedded files.","title":"Denial of Service Vulnerability in pypdf","url":"https://feed.craftedsignal.io/briefs/2026-10-pypdf-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:py-Pdf:pypdf:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}