<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Pypdf (&lt; 6.18.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/pypdf--6.18.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 20:23:09 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/pypdf--6.18.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>pypdf Memory Exhaustion Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-10-pypdf-memory-exhaustion/</link><pubDate>Thu, 01 Oct 2026 20:23:09 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-pypdf-memory-exhaustion/</guid><description>A vulnerability in the pypdf library, tracked as CVE-2026-103000, allows attackers to trigger excessive memory consumption and potential denial of service by providing crafted PDFs with large alphabetical page labels.</description><content:encoded><![CDATA[<p>The pypdf library contains a vulnerability, identified as CVE-2026-103000, that exposes applications to a denial-of-service (DoS) condition. The issue resides in the handling of alphabetical page labels within PDF documents. When the library processes a document containing specifically crafted, excessively large alphabetical page labels, it triggers a disproportionate increase in memory usage. This can lead to service instability, resource exhaustion, or application crashes depending on the environment where the library is deployed. This vulnerability affects all versions of pypdf prior to 6.19.0. Organizations using pypdf to process untrusted or user-uploaded PDF files are at risk and should prioritize upgrading to the patched version or applying the recommended code changes.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in a denial-of-service state for the application processing the malicious PDF. This is particularly concerning for document management systems, web scrapers, or any automated pipeline that parses user-provided PDFs. If the host environment has constrained memory, a single crafted file could induce a crash, disrupting service availability.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the pypdf library to version 6.19.0 or later immediately to incorporate the patch for CVE-2026-103000.</li>
<li>If an immediate upgrade is not possible, apply the code changes provided in the vendor pull request (PR #4096) to sanitize or limit the processing of page labels.</li>
<li>Implement memory limits (e.g., cgroups, container memory limits) on processes responsible for parsing untrusted PDF files to mitigate the impact of potential resource exhaustion attacks.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>denial-of-service</category><category>pypdf</category><category>memory-exhaustion</category><category>cve-2026-103000</category></item><item><title>Denial of Service Vulnerability in pypdf</title><link>https://feed.craftedsignal.io/briefs/2026-10-pypdf-dos/</link><pubDate>Thu, 01 Oct 2026 20:22:57 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-pypdf-dos/</guid><description>The pypdf library contains a vulnerability, CVE-2026-102999, that allows an attacker to cause excessive execution times by providing a crafted PDF with numerous embedded files.</description><content:encoded><![CDATA[<p>The pypdf library is susceptible to a denial-of-service condition identified as CVE-2026-102999. This vulnerability stems from inefficient handling of embedded files within PDF documents. When an application uses the library's dictionary-based API to access embedded files, a specially crafted PDF containing a large number of these objects can trigger a performance degradation, resulting in excessively long runtimes and potential service exhaustion. This issue affects all versions of pypdf prior to 6.19.0. Organizations processing untrusted or user-supplied PDF documents using this library are at risk of resource depletion attacks targeting their document processing pipelines.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in a denial-of-service condition where the application becomes unresponsive due to the excessive computational load required to process the malicious PDF. This impacts any system or automated service that parses, extracts, or inspects embedded content from PDF files using affected versions of pypdf.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for development and security teams:</p>
<ul>
<li>Upgrade the pypdf dependency to version 6.19.0 or later to include the fix for CVE-2026-102999.</li>
<li>If upgrading is not immediately feasible, apply the patches provided in PR #4081 to mitigate the excessive runtime behavior.</li>
<li>Implement resource limits, such as execution timeouts or CPU usage quotas, for processes that invoke pypdf on untrusted input files.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>vulnerability</category><category>dos</category><category>denial-of-service</category><category>library-vulnerability</category><category>python</category></item></channel></rss>