
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27026 is a denial-of-service vulnerability in pypdf, a free and open-source pure-Python PDF library, caused by unbounded resource consumption during FlateDecode stream decompression. An attacker can craft a malformed PDF with a /FlateDecode stream that triggers an inefficient byte-by-byte decompression fallback path, leading to excessive CPU usage and long runtimes. All pypdf versions prior to 6.7.1 are affected; the vulnerability was disclosed on February 17, 2026, and published to the GitHub Advisory Database on February 18, 2026. It carries a CVSS v3.1 score of 5.5 (Medium) and a CVSS v4.0 score of 6.9 (Medium) (GitHub Advisory, Red Hat Bugzilla).
The root cause is classified under CWE-770 (Allocation of Resources Without Limits or Throttling) and CWE-1050 (Excessive Platform Resource Consumption within a Loop). When pypdf encounters a malformed /FlateDecode compressed stream that fails standard zlib decompression, it falls back to a byte-by-byte decompression recovery loop with no upper bound on the number of bytes processed. Prior to the fix, this loop could iterate over arbitrarily large malformed inputs without any limit, causing the application to hang. The fix introduced a new constant ZLIB_MAX_RECOVERY_INPUT_LENGTH (defaulting to 5 MB) that caps the number of bytes processed in the recovery path, raising a LimitReachedError when exceeded (GitHub Commit, GitHub PR #3644).
Successful exploitation causes a denial-of-service condition where the application processing the malicious PDF becomes unresponsive or hangs for an extended period due to CPU exhaustion. There is no impact on confidentiality or integrity — only availability is affected. In environments where pypdf is used to process user-supplied PDFs (e.g., document management systems, web services), this could render the service unavailable to legitimate users (GitHub Advisory, Red Hat Bugzilla).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.014% (0th percentile), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only local access and low privileges (or the ability to submit a crafted PDF to a system running vulnerable pypdf versions), making the attack surface relatively narrow (GitHub Advisory).
/FlateDecode stream with malformed compressed data — specifically, data that fails standard zlib decompression and triggers the byte-by-byte recovery fallback in pypdf's decompress() function._decompress_with_limit() call fails, and the fallback loop begins processing the input byte-by-byte without any limit on the number of recovery attempts.LimitReachedError exceptions in pypdf logs (only on patched versions)./FlateDecode streams that fail standard decompression.The primary remediation is to upgrade pypdf to version 6.7.1 or later, which introduces the ZLIB_MAX_RECOVERY_INPUT_LENGTH constant (defaulting to 5 MB) to cap the byte-by-byte recovery loop. For organizations unable to upgrade immediately, the changes from PR #3644 can be applied manually as a workaround. Additional interim mitigations include restricting PDF processing to trusted sources, implementing timeouts and resource quotas for PDF decompression operations, and sandboxing PDF processing to limit broader system impact (GitHub Advisory, GitHub PR #3644).
IBM issued security bulletins acknowledging the impact of CVE-2026-27026 on IBM watsonx Orchestrate Developer Edition and related products, recommending customers apply available patches (IBM Advisory, IBM Advisory). Red Hat tracked the issue via Bugzilla and assigned it medium severity (Red Hat Bugzilla). The vulnerability was also picked up by OpenSUSE and Oracle security update channels, indicating broad downstream awareness across the open-source ecosystem.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."