Infinite Loop Vulnerability in pypdf Library by py-pdf
CVE-2026-27628
1.2LOW
What is CVE-2026-27628?
The pypdf library, a popular open-source pure-Python PDF manipulation tool, is susceptible to an infinite loop vulnerability. An attacker can craft a malicious PDF that triggers this vulnerability when the file is opened, leading to excessive resource consumption and potential denial of service. This issue has been addressed in pypdf version 6.7.2, and users are advised to upgrade to this version or apply the available patch manually to mitigate the risk.
Affected Version(s)
pypdf < 6.7.2
