CVE-2026-102997High· 8.7▾ Twilightpypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF containing a partially malformed /FlateDecode stream with padded data can force pypdf/filters.py to use inefficient byte-by-byte decompression while …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF containing a partially malformed /FlateDecode stream with padded data can force pypdf/filters.py to use inefficient byte-by-byte decompression while the earlier recovery counter fails to advance for bytes that successfully decode, causing long runtimes and application unavailability. This is a residual issue after the malformed FlateDecode recovery fix. This issue is fixed in version 6.18.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102999High· 8.7pypdf is a free and open-source pure-python PDF library
CVE-2026-102996High· 8.7pypdf is a free and open-source pure-python PDF library
CVE-2026-102995High· 8.7pypdf is a free and open-source pure-python PDF library
CVE-2026-102994High· 8.7pypdf is a free and open-source pure-python PDF library
CVE-2026-103000High· 8.7pypdf is a free and open-source pure-python PDF library
CVE-2026-102998High· 8.7pypdf is a free and open-source pure-python PDF library