CVE-2026-27888: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-27888 is a denial-of-service vulnerability in pypdf, a free and open-source pure-Python PDF library, that allows an unauthenticated remote attacker to exhaust system RAM by supplying a crafted PDF file. The vulnerability affects all pypdf versions prior to 6.7.3 and was disclosed on February 24–26, 2026, with the fix released on February 24, 2026. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 6.6 (Medium) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is uncontrolled resource consumption (CWE-400, CWE-1050) during decompression of XFA stream data. When the xfa property of a PdfReader or PdfWriter object is accessed, pypdf previously called zlib.decompress() without any output size limit on the stream data. An attacker can craft a PDF containing an XFA stream compressed with /FlateDecode that expands to an arbitrarily large payload (a "zip bomb" style attack), causing the process to allocate unbounded RAM until the system is exhausted. The fix in PR #3658 replaces the unbounded zlib.decompress() call with a _decompress_with_limit() helper that enforces a maximum decompression output length (ZLIB_MAX_OUTPUT_LENGTH), raising a LimitReachedError if the limit is exceeded (GitHub Advisory, Fix Commit).

Impact

Successful exploitation causes the host process to exhaust available RAM, resulting in a denial of service — the application becomes unresponsive or crashes. There is no impact on confidentiality or integrity; the vulnerability is purely an availability issue. Any application or service that processes attacker-supplied PDF files and accesses the xfa property is at risk, including document management systems, PDF processing pipelines, and AI/ML platforms such as IBM watsonx Orchestrate that bundle pypdf as a dependency (GitHub Advisory, IBM Advisory).

Exploitability

No public proof-of-concept exploit code has been reported, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.042%, reflecting low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Despite the lack of active exploitation, the attack requires no authentication, no user interaction, and no special privileges, making it straightforward to attempt against any internet-exposed service that processes PDF files with pypdf (GitHub Advisory, Feedly).

Exploitation steps

  1. Craft a malicious PDF: Create a PDF file containing an AcroForm with an XFA array entry. Embed a /FlateDecode-compressed stream whose decompressed content is extremely large (e.g., millions of repeated bytes), exploiting the high compression ratio of zlib to produce a small file that expands to gigabytes in memory.
  2. Deliver the PDF to the target: Submit the crafted PDF to any service or application that uses pypdf (< 6.7.3) to process user-supplied documents — for example, via a file upload endpoint, email attachment processor, or API.
  3. Trigger XFA property access: Ensure the application code accesses the xfa property of a PdfReader or PdfWriter instance while processing the uploaded file. This is the code path that invokes the unbounded zlib.decompress() call.
  4. RAM exhaustion: The decompression of the crafted stream consumes all available RAM, causing the process (and potentially the host) to become unresponsive or crash, achieving denial of service (GitHub Advisory, Fix Commit).

Indicators of compromise

  • Process Behavior: Sudden and sustained spike in memory consumption by the Python process running pypdf, potentially reaching system RAM limits and triggering OOM (out-of-memory) killer events.
  • Logs: Application crash logs or OOM kernel messages (e.g., Out of memory: Kill process in /var/log/syslog or dmesg) coinciding with PDF processing activity.
  • File System: Presence of unusually small PDF files (a few KB) submitted to the application that contain /FlateDecode-compressed XFA streams — these can be identified by inspecting uploaded PDF content for /XFA entries within /AcroForm dictionaries.
  • Network: Repeated upload requests delivering small PDF files to document processing endpoints, particularly if followed by service unavailability.

Mitigation and workarounds

Upgrade pypdf to version 6.7.3 or later, which enforces a decompression size limit via the _decompress_with_limit() function when processing XFA streams (pypdf Release). If an immediate upgrade is not possible, manually apply the changes from PR #3658 (commit 7a4c8246ed48d9d328fb596942271da47b6d109c) to the local pypdf installation (Fix PR). As an additional operational control, monitor applications using pypdf for unexpected high memory consumption and consider restricting or sandboxing PDF processing workloads that handle untrusted input.

Community reactions

Red Hat tracked the vulnerability via Bugzilla (Bug 2442899) and assigned it medium severity. IBM issued advisories for affected products including watsonx Orchestrate Developer Edition and watsonx Orchestrate with watsonx Assistant Cartridge (IBM Advisory, IBM Advisory 2). OpenSUSE published a security announcement for pypdf2, and Oracle included the CVE in its April 2026 security bulletin. Community discussion was limited, with brief mentions on Bluesky and Mastodon, reflecting the moderate severity and lack of active exploitation.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

pypdf2

Affected

sid

pypdf: 6.9.0-1

Fixed

trixie

pypdf

Affected

Ubuntu

Unknown

devel

pypdf

Unknown

noble

pypdf

Unknown

noble (esm-apps)

pypdf

Unknown

resolute

pypdf

Unknown

resolute (esm-apps)

pypdf

Unknown

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management