CVE-2026-102999

pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF containing many embedded files can cause the dictionary-based attachments API in pypdf/_doc_common.py to reparse the full attachment list for each content lookup, producing repeated work and long runtimes when an application accesses the embedded-file mapping. This issue is fixed in version 6.19.0.

  • Published Sep 30, 2026
  • CVSS 8.7 high
  • 0.3% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-102999 at the National Vulnerability Database