Infinite Loop Vulnerability in pypdf Library by py-pdf
CVE-2026-27628

1.2LOW

Key Information:

Vendor

Py-PDF

Status
Vendor
CVE Published:
25 February 2026

What is CVE-2026-27628?

The pypdf library, a popular open-source pure-Python PDF manipulation tool, is susceptible to an infinite loop vulnerability. An attacker can craft a malicious PDF that triggers this vulnerability when the file is opened, leading to excessive resource consumption and potential denial of service. This issue has been addressed in pypdf version 6.7.2, and users are advised to upgrade to this version or apply the available patch manually to mitigate the risk.

Affected Version(s)

pypdf < 6.7.2

References

CVSS V4

Score:
1.2
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.