CVE-2026-28351: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-28351 is an uncontrolled resource consumption vulnerability in pypdf, a free and open-source pure-Python PDF library, that allows remote unauthenticated attackers to cause excessive memory usage via a crafted PDF file. The vulnerability affects all pypdf versions prior to 6.7.4 and was disclosed on February 27, 2026, by researcher bugbunny-research and analyzed by stefan6419846. It carries a CVSS v3.1 base score of 5.3 (Medium) and a CVSS v4.0 base score of 6.9 (Medium) (Github Advisory, pypdf Security Advisory).

Technical details

The root cause is classified as CWE-400 (Uncontrolled Resource Consumption). The vulnerability exists in pypdf's RunLengthDecode filter implementation within pypdf/filters.py, which lacked any limit on the total output length during decompression. An attacker can craft a malicious PDF with a specially constructed RunLengthDecode content stream — for example, using repeated run-length encoded sequences (e.g., b"\x81A" * runs) — that, when parsed, causes the library to expand data into arbitrarily large in-memory byte arrays without bound. The fix introduced a configurable constant RUN_LENGTH_MAX_OUTPUT_LENGTH (defaulting to 75 MB) and raises a LimitReachedError if the decompressed output exceeds this threshold (pypdf PR #3664, Patch Commit).

Impact

Successful exploitation causes a denial-of-service (DoS) condition by exhausting system memory on any host running a vulnerable pypdf version. Applications that accept and process user-supplied PDF files — such as document management systems, web services, or AI/ML pipelines — are at risk of crashing or becoming unresponsive. There is no impact on confidentiality or integrity; the vulnerability is limited to availability. IBM watsonx Orchestrate products that bundle pypdf are also affected (Github Advisory, IBM Advisory).

Exploitability

No public proof-of-concept exploit code has been published, and there is no evidence of in-the-wild exploitation at this time. The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it trivially exploitable against any internet-facing service that parses attacker-supplied PDFs with pypdf. The EPSS score is approximately 0.049% (0.000490), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory).

Exploitation steps

  1. Craft a malicious PDF: Create a PDF file containing a content stream encoded with the RunLengthDecode filter. Use repeated run-length encoded byte sequences (e.g., b"\x81A" * N where N is large enough to produce output exceeding 75 MB) followed by an EOD marker (b"\x80") to maximize memory expansion.
  2. Deliver the PDF to the target: Submit the crafted PDF to any service or application that uses a vulnerable version of pypdf (< 6.7.4) to parse PDF content — for example, via a file upload endpoint, email attachment processor, or API.
  3. Trigger parsing: Cause the application to parse the PDF's content stream, which invokes the RunLengthDecode.decode() method in pypdf/filters.py.
  4. Memory exhaustion: The decoder iterates over the encoded data and appends decompressed bytes to an in-memory list without any size check, causing RAM to be consumed until the process crashes or the system runs out of memory, resulting in a DoS condition (pypdf PR #3664, Patch Commit).

Indicators of compromise

  • Logs: Application logs showing MemoryError, out-of-memory (OOM) exceptions, or LimitReachedError (in patched versions) during PDF parsing operations; sudden process crashes or restarts correlated with PDF upload/processing events.
  • System: Rapid spike in memory consumption by the Python process handling PDF parsing, potentially triggering OOM killer events visible in /var/log/syslog or dmesg on Linux systems.
  • File System: Presence of unusually large or malformed PDF files in upload directories or temporary processing folders, particularly those with minimal file size but triggering high memory usage.
  • Network: Repeated submission of the same or similar PDF files to a document processing endpoint from a single source IP, especially if followed by service unavailability.

Mitigation and workarounds

The primary remediation is to upgrade pypdf to version 6.7.4 or later, which introduces the RUN_LENGTH_MAX_OUTPUT_LENGTH constant (defaulting to 75 MB) to cap decompressed output size (pypdf Release 6.7.4). For deployments that cannot upgrade immediately, apply the changes from PR #3664 manually to add the output length limit to the RunLengthDecode.decode() method (pypdf PR #3664). Additional defensive measures include restricting PDF input to trusted sources only, setting OS-level memory limits on PDF processing processes, and monitoring applications for abnormal memory consumption patterns. IBM watsonx Orchestrate users should refer to the IBM advisories for product-specific patch guidance (IBM Advisory, IBM Advisory 2).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

pypdf2

Affected

sid

pypdf: 6.9.0-1

Fixed

trixie

pypdf

Affected

Ubuntu

Unknown

bionic (esm-apps)

pypdf2

Unknown

devel

pypdf

Unknown

focal (esm-apps)

pypdf2

Unknown

jammy

pypdf2

Unknown

jammy (esm-apps)

pypdf2

Unknown

noble

pypdf

Unknown

noble (esm-apps)

pypdf

Unknown

resolute

pypdf

Unknown

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management