
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27628 is an infinite loop (denial of service) vulnerability in pypdf, a free and open-source pure-Python PDF library. An attacker can craft a malicious PDF file containing circular /Prev references in cross-reference (xref) streams that, when read by the library, causes the application to enter an unreachable exit condition loop indefinitely. All versions of pypdf prior to 6.7.2 are affected. The vulnerability was reported by researcher rampageservices, published to the GitHub Advisory Database on February 22, 2026, and assigned CVE-2026-27628 on February 25, 2026. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 1.2 (Low) (Github Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-835 (Loop with Unreachable Exit Condition). The vulnerable function _read_xref_tables_and_trailers() in pypdf/_reader.py follows /Prev pointers in the PDF cross-reference (xref) chain using a while startxref is not None loop, but lacks any mechanism to detect already-visited offsets. A malformed PDF can encode a circular xref chain (e.g., xref A → /Prev → xref B → /Prev → xref A), causing the loop to run forever while repeatedly re-parsing and re-caching the same objects and spamming "Overwriting cache for N M" warnings. The fix, applied in commit 0fbd959, introduces a visited_xref_offsets set that tracks seen offsets and breaks the loop with a warning upon detecting a cycle — the same pattern used elsewhere in pypdf for cycle detection (pypdf Issue #3654, pypdf Commit).
Successful exploitation results in a denial of service condition: the affected Python process hangs at 100% CPU utilization indefinitely and must be killed manually. There is no impact on confidentiality or integrity — the vulnerability is purely availability-based. Any application or service that uses pypdf to process PDFs from untrusted sources (e.g., web document processors, file upload handlers, automated pipelines) is at risk of being rendered completely unresponsive by a single malicious file (Github Advisory, Red Hat Bugzilla).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (Github Advisory). The EPSS score is approximately 0.04–0.055%, placing it in the 18th percentile for exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. The attack requires no authentication or privileges, but does require user interaction in the form of the target application reading the crafted PDF file.
/Prev reference chain in its cross-reference (xref) structure — for example, xref table at offset A contains /Prev pointing to offset B, and xref table at offset B contains /Prev pointing back to offset A.PdfReader() on the malicious file, which invokes _read_xref_tables_and_trailers() in pypdf/_reader.py.while startxref is not None loop follows the circular /Prev chain indefinitely, consuming 100% CPU and causing the process to hang, rendering the service unresponsive (pypdf Issue #3654, pypdf Commit)."Overwriting cache for N M" warning messages in application logs originating from the pypdf library, indicating the same xref objects are being re-parsed in a loop.The primary remediation is to upgrade pypdf to version 6.7.2 or later, which includes the fix for circular xref chain detection (Github Advisory). For systems that cannot be updated immediately, the patch from PR #3655 can be applied manually to earlier versions by adding a visited_xref_offsets set in _read_xref_tables_and_trailers() in pypdf/_reader.py (pypdf Commit). As additional protective measures, implement timeouts on PDF parsing operations and restrict or validate PDF files from untrusted sources before processing. IBM has also issued advisories for affected watsonx Orchestrate products (IBM Advisory).
The vulnerability received brief coverage on social media platforms including Mastodon and Bluesky via security news accounts shortly after disclosure. Red Hat tracked the issue via Bugzilla and assigned it medium priority/severity. Oracle included it in their April 2026 security bulletin, and IBM issued advisories for affected watsonx Orchestrate products. No significant researcher commentary or major media coverage beyond standard vulnerability aggregation sites has been observed (Red Hat Bugzilla, Oracle Advisory, IBM Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."