CVE-2026-102994: pypdf: Possible long runtimes/large memory usage when parsing indirect objects
pypdf is a free and open-source pure-python PDF library. Prior to 6.18.0, a crafted PDF containing indirect-object identifiers or generation-number tokens that continue for a long time without whitespace can cause pypdf/reader.py and pypdf/generic/base.py to scan excessive input through readuntilwhitespace, resulting in long runtimes and application unavailability. This issue is fixed in version 6.18.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pypdfto a version that resolves this vulnerability.Fixed in 6.18.0