CVE-2026-27026: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-27026 is a denial-of-service vulnerability in pypdf, a free and open-source pure-Python PDF library, caused by unbounded resource consumption during FlateDecode stream decompression. An attacker can craft a malformed PDF with a /FlateDecode stream that triggers an inefficient byte-by-byte decompression fallback path, leading to excessive CPU usage and long runtimes. All pypdf versions prior to 6.7.1 are affected; the vulnerability was disclosed on February 17, 2026, and published to the GitHub Advisory Database on February 18, 2026. It carries a CVSS v3.1 score of 5.5 (Medium) and a CVSS v4.0 score of 6.9 (Medium) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified under CWE-770 (Allocation of Resources Without Limits or Throttling) and CWE-1050 (Excessive Platform Resource Consumption within a Loop). When pypdf encounters a malformed /FlateDecode compressed stream that fails standard zlib decompression, it falls back to a byte-by-byte decompression recovery loop with no upper bound on the number of bytes processed. Prior to the fix, this loop could iterate over arbitrarily large malformed inputs without any limit, causing the application to hang. The fix introduced a new constant ZLIB_MAX_RECOVERY_INPUT_LENGTH (defaulting to 5 MB) that caps the number of bytes processed in the recovery path, raising a LimitReachedError when exceeded (GitHub Commit, GitHub PR #3644).

Impact

Successful exploitation causes a denial-of-service condition where the application processing the malicious PDF becomes unresponsive or hangs for an extended period due to CPU exhaustion. There is no impact on confidentiality or integrity — only availability is affected. In environments where pypdf is used to process user-supplied PDFs (e.g., document management systems, web services), this could render the service unavailable to legitimate users (GitHub Advisory, Red Hat Bugzilla).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.014% (0th percentile), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only local access and low privileges (or the ability to submit a crafted PDF to a system running vulnerable pypdf versions), making the attack surface relatively narrow (GitHub Advisory).

Exploitation steps

  1. Craft a malicious PDF: Create a PDF file containing a /FlateDecode stream with malformed compressed data — specifically, data that fails standard zlib decompression and triggers the byte-by-byte recovery fallback in pypdf's decompress() function.
  2. Submit the PDF: Provide the crafted PDF to any system or application that uses a vulnerable version of pypdf (< 6.7.1) to process PDF files, such as a document upload endpoint, a PDF parsing script, or a batch processing pipeline.
  3. Trigger the vulnerability: When pypdf attempts to decompress the malformed stream, the standard _decompress_with_limit() call fails, and the fallback loop begins processing the input byte-by-byte without any limit on the number of recovery attempts.
  4. Achieve denial of service: The unbounded loop consumes excessive CPU resources, causing the application thread or process to hang for an extended period, effectively denying service to legitimate users (GitHub Advisory, GitHub Commit).

Indicators of compromise

  • Process: Python processes consuming abnormally high CPU for extended periods while processing PDF files; processes that appear hung or unresponsive during PDF decompression operations.
  • Logs: Application logs showing repeated or stalled PDF processing jobs; timeout errors or watchdog alerts triggered during PDF parsing; LimitReachedError exceptions in pypdf logs (only on patched versions).
  • File System: Presence of unusually large or malformed PDF files submitted to the system, particularly those with /FlateDecode streams that fail standard decompression.
  • Network: In web-facing deployments, repeated uploads of the same or similar malformed PDF files from a single source IP, potentially indicating a targeted DoS attempt.

Mitigation and workarounds

The primary remediation is to upgrade pypdf to version 6.7.1 or later, which introduces the ZLIB_MAX_RECOVERY_INPUT_LENGTH constant (defaulting to 5 MB) to cap the byte-by-byte recovery loop. For organizations unable to upgrade immediately, the changes from PR #3644 can be applied manually as a workaround. Additional interim mitigations include restricting PDF processing to trusted sources, implementing timeouts and resource quotas for PDF decompression operations, and sandboxing PDF processing to limit broader system impact (GitHub Advisory, GitHub PR #3644).

Community reactions

IBM issued security bulletins acknowledging the impact of CVE-2026-27026 on IBM watsonx Orchestrate Developer Edition and related products, recommending customers apply available patches (IBM Advisory, IBM Advisory). Red Hat tracked the issue via Bugzilla and assigned it medium severity (Red Hat Bugzilla). The vulnerability was also picked up by OpenSUSE and Oracle security update channels, indicating broad downstream awareness across the open-source ecosystem.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

pypdf2

Affected

sid

pypdf: 6.9.0-1

Fixed

trixie

pypdf

Affected

Ubuntu

Unknown

bionic (esm-apps)

pypdf2

Unknown

devel

pypdf

Unknown

focal (esm-apps)

pypdf2

Unknown

jammy

pypdf2

Unknown

jammy (esm-apps)

pypdf2

Unknown

noble

pypdf

Unknown

noble (esm-apps)

pypdf

Unknown

resolute

pypdf

Unknown

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management