CVE-2026-27025: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-27025 is a Denial of Service vulnerability in the pypdf Python PDF library caused by unbounded iteration when parsing /ToUnicode font entries in crafted PDF files. It affects all pypdf versions prior to 6.7.1 and was disclosed on February 17, 2026, by researcher CheonWoong-Park and analyzed by stefan6419846. The vulnerability carries a CVSS v3.1 score of 5.5 (Medium) and a CVSS v4.0 score of 6.9 (Medium) (GitHub Advisory, Red Hat Bugzilla). Downstream products including IBM watsonx Orchestrate Developer Edition and related cartridges are also affected (GitHub Advisory).

Technical details

The root cause is excessive iteration (CWE-834, CWE-1050) in pypdf's /ToUnicode CMap parsing logic within pypdf/_cmap.py. When processing bfrange or bfchar entries in a font's /ToUnicode stream, the library iterates over all specified character mappings without enforcing an upper bound on the mapping dictionary size. An attacker can craft a PDF with a /ToUnicode entry specifying an extremely large range (e.g., <00000000> <001FFFFF> <00000000>, yielding over 2 million entries) that triggers runaway CPU and memory consumption during text extraction. The fix introduced a MAPPING_DICTIONARY_SIZE_LIMIT of 100,000 entries and a _check_mapping_size() guard that raises a LimitReachedError when exceeded (pypdf commit, pypdf PR #3646).

Impact

Successful exploitation causes the affected application to consume excessive CPU cycles and memory, resulting in denial of service — the application becomes unresponsive, hangs, or crashes. There is no impact on confidentiality or integrity; the vulnerability is limited to availability of the system processing the malicious PDF. Applications that automatically process user-supplied PDFs (e.g., document pipelines, AI/ML ingestion workflows) are at elevated risk of service disruption (GitHub Advisory, Red Hat Bugzilla).

Exploitability

No public proof-of-concept exploit code has been observed, and there is no evidence of in-the-wild exploitation as of the time of disclosure (GitHub Advisory). The EPSS score is approximately 0.014% (0th percentile), indicating very low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires only local access and low privileges (CVSS v3.1), though the CVSS v4.0 assessment notes no privileges are required to trigger the condition once a malicious PDF is processed.

Exploitation steps

  1. Craft a malicious PDF: Create a PDF file containing a font object with a /ToUnicode CMap stream that specifies an extremely large bfrange entry, such as <00000000> <001FFFFF> <00000000>, which defines over 2 million character mappings.
  2. Deliver the PDF: Place the crafted PDF in a location accessible to the target application — for example, upload it to a document processing service, drop it in a watched directory, or supply it as input to a script using pypdf for text extraction.
  3. Trigger parsing: Cause the vulnerable application to process the PDF, particularly via a text extraction operation (e.g., page.extract_text()), which invokes the parse_bfrange or parse_bfchar functions in pypdf/_cmap.py.
  4. Achieve denial of service: The unbounded iteration over the oversized mapping dictionary exhausts CPU and memory resources, causing the application to hang or crash (pypdf commit, GitHub Advisory).

Indicators of compromise

  • Process: Python processes consuming abnormally high CPU or memory while processing PDF files; processes that hang indefinitely without completing.
  • Logs: Application-level errors or timeouts during PDF text extraction operations; LimitReachedError exceptions in patched versions indicating attempted exploitation.
  • File System: Presence of unusually structured PDF files with /ToUnicode CMap streams containing very large bfrange or bfchar entries (e.g., ranges spanning millions of code points).
  • Network: Unexpected uploads of PDF files to document processing endpoints, particularly from untrusted or external sources.

Mitigation and workarounds

The primary remediation is to upgrade pypdf to version 6.7.1 or later, which enforces a hard limit of 100,000 entries on /ToUnicode mapping dictionaries (GitHub Advisory, pypdf PR #3646). If immediate upgrade is not possible, manually apply the changes from PR #3646 to add the _check_mapping_size() guard. Additional mitigations include restricting PDF processing to trusted sources only, implementing processing timeouts, and monitoring resource consumption during PDF parsing. IBM has released patches for affected watsonx Orchestrate products (IBM Advisory).

Community reactions

The vulnerability was reported by researcher CheonWoong-Park and analyzed and patched by pypdf maintainer stefan6419846 on the same day (February 17, 2026), demonstrating a rapid response from the open-source project (GitHub Advisory). Red Hat tracked the issue via Bugzilla and rated it medium severity (Red Hat Bugzilla). No significant broader media coverage or notable social media discussion has been identified for this vulnerability.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

pypdf2

Affected

sid

pypdf: 6.9.0-1

Fixed

trixie

pypdf

Affected

Ubuntu

Unknown

bionic (esm-apps)

pypdf2

Unknown

devel

pypdf

Unknown

focal (esm-apps)

pypdf2

Unknown

jammy

pypdf2

Unknown

jammy (esm-apps)

pypdf2

Unknown

noble

pypdf

Unknown

noble (esm-apps)

pypdf

Unknown

resolute

pypdf

Unknown

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management