CVE-2026-27628: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-27628 is an infinite loop (denial of service) vulnerability in pypdf, a free and open-source pure-Python PDF library. An attacker can craft a malicious PDF file containing circular /Prev references in cross-reference (xref) streams that, when read by the library, causes the application to enter an unreachable exit condition loop indefinitely. All versions of pypdf prior to 6.7.2 are affected. The vulnerability was reported by researcher rampageservices, published to the GitHub Advisory Database on February 22, 2026, and assigned CVE-2026-27628 on February 25, 2026. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 1.2 (Low) (Github Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-835 (Loop with Unreachable Exit Condition). The vulnerable function _read_xref_tables_and_trailers() in pypdf/_reader.py follows /Prev pointers in the PDF cross-reference (xref) chain using a while startxref is not None loop, but lacks any mechanism to detect already-visited offsets. A malformed PDF can encode a circular xref chain (e.g., xref A → /Prev → xref B → /Prev → xref A), causing the loop to run forever while repeatedly re-parsing and re-caching the same objects and spamming "Overwriting cache for N M" warnings. The fix, applied in commit 0fbd959, introduces a visited_xref_offsets set that tracks seen offsets and breaks the loop with a warning upon detecting a cycle — the same pattern used elsewhere in pypdf for cycle detection (pypdf Issue #3654, pypdf Commit).

Impact

Successful exploitation results in a denial of service condition: the affected Python process hangs at 100% CPU utilization indefinitely and must be killed manually. There is no impact on confidentiality or integrity — the vulnerability is purely availability-based. Any application or service that uses pypdf to process PDFs from untrusted sources (e.g., web document processors, file upload handlers, automated pipelines) is at risk of being rendered completely unresponsive by a single malicious file (Github Advisory, Red Hat Bugzilla).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (Github Advisory). The EPSS score is approximately 0.04–0.055%, placing it in the 18th percentile for exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. The attack requires no authentication or privileges, but does require user interaction in the form of the target application reading the crafted PDF file.

Exploitation steps

  1. Craft a malicious PDF: Create a PDF file with a circular /Prev reference chain in its cross-reference (xref) structure — for example, xref table at offset A contains /Prev pointing to offset B, and xref table at offset B contains /Prev pointing back to offset A.
  2. Deliver the PDF to the target: Submit the crafted PDF to any service or application that uses pypdf to read or process PDF files (e.g., upload it via a web form, email attachment, or API endpoint).
  3. Trigger parsing: The target application calls PdfReader() on the malicious file, which invokes _read_xref_tables_and_trailers() in pypdf/_reader.py.
  4. Infinite loop executes: The while startxref is not None loop follows the circular /Prev chain indefinitely, consuming 100% CPU and causing the process to hang, rendering the service unresponsive (pypdf Issue #3654, pypdf Commit).

Indicators of compromise

  • Process: Python process consuming sustained 100% CPU without completing, associated with a PDF parsing operation; process must be killed externally.
  • Logs: Repeated "Overwriting cache for N M" warning messages in application logs originating from the pypdf library, indicating the same xref objects are being re-parsed in a loop.
  • Application Behavior: PDF processing requests that never return a response or time out; worker threads or processes becoming permanently blocked on a single file read operation (pypdf Issue #3654).

Mitigation and workarounds

The primary remediation is to upgrade pypdf to version 6.7.2 or later, which includes the fix for circular xref chain detection (Github Advisory). For systems that cannot be updated immediately, the patch from PR #3655 can be applied manually to earlier versions by adding a visited_xref_offsets set in _read_xref_tables_and_trailers() in pypdf/_reader.py (pypdf Commit). As additional protective measures, implement timeouts on PDF parsing operations and restrict or validate PDF files from untrusted sources before processing. IBM has also issued advisories for affected watsonx Orchestrate products (IBM Advisory).

Community reactions

The vulnerability received brief coverage on social media platforms including Mastodon and Bluesky via security news accounts shortly after disclosure. Red Hat tracked the issue via Bugzilla and assigned it medium priority/severity. Oracle included it in their April 2026 security bulletin, and IBM issued advisories for affected watsonx Orchestrate products. No significant researcher commentary or major media coverage beyond standard vulnerability aggregation sites has been observed (Red Hat Bugzilla, Oracle Advisory, IBM Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

pypdf2

Affected

sid

pypdf: 6.9.0-1

Fixed

trixie

pypdf

Affected

Ubuntu

Unknown

bionic (esm-apps)

pypdf2

Unknown

devel

pypdf

Unknown

focal (esm-apps)

pypdf2

Unknown

jammy

pypdf2

Unknown

jammy (esm-apps)

pypdf2

Unknown

noble

pypdf

Unknown

noble (esm-apps)

pypdf

Unknown

resolute

pypdf

Unknown

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
GHSA-jqmf-mx4f-hfr6CRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
GHSA-8mcx-5rqc-vhmfHIGH8.8
  • Python logoPython
  • dulwich
NoYesOct 02, 2026
GHSA-5rmq-chc7-m22fHIGH7.5
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
GHSA-35mr-4567-66vgMEDIUM6.5
  • Python logoPython
  • dulwich
NoYesOct 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management