{"id":"CVE-2026-102997","aliases":["GHSA-jw7q-gvrg-4vj3","PYSEC-2026-4156"],"url":"https://o3.security/vulnerability/CVE-2026-102997","summary":"pypdf: Possible long runtimes for partially malformed FlateDecode streams (Follow-up)","details":"pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF containing a partially malformed /FlateDecode stream with padded data can force pypdf/filters.py to use inefficient byte-by-byte decompression while the earlier recovery counter fails to advance for bytes that successfully decode, causing long runtimes and application unavailability. This is a residual issue after the malformed FlateDecode recovery fix. This issue is fixed in version 6.18.1.","published":"2026-09-30T20:05:51.538Z","modified":"2026-10-04T02:30:17.310777071Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"pypdf","fixedVersion":"6.18.1"}],"fix":{"url":"https://github.com/py-pdf/pypdf/commit/d9d38cf99b115deb562d3b68f36c33027bc04f79","label":"py-pdf/pypdf@d9d38cf"},"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.18.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102997.json"},{"type":"ADVISORY","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-jw7q-gvrg-4vj3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102997"},{"type":"FIX","url":"https://github.com/py-pdf/pypdf/commit/d9d38cf99b115deb562d3b68f36c33027bc04f79"},{"type":"FIX","url":"https://github.com/py-pdf/pypdf/pull/4073"},{"type":"PACKAGE","url":"https://github.com/py-pdf/pypdf"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-10-04T02:30:17.310777071Z"}}