
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28351 is an uncontrolled resource consumption vulnerability in pypdf, a free and open-source pure-Python PDF library, that allows remote unauthenticated attackers to cause excessive memory usage via a crafted PDF file. The vulnerability affects all pypdf versions prior to 6.7.4 and was disclosed on February 27, 2026, by researcher bugbunny-research and analyzed by stefan6419846. It carries a CVSS v3.1 base score of 5.3 (Medium) and a CVSS v4.0 base score of 6.9 (Medium) (Github Advisory, pypdf Security Advisory).
The root cause is classified as CWE-400 (Uncontrolled Resource Consumption). The vulnerability exists in pypdf's RunLengthDecode filter implementation within pypdf/filters.py, which lacked any limit on the total output length during decompression. An attacker can craft a malicious PDF with a specially constructed RunLengthDecode content stream — for example, using repeated run-length encoded sequences (e.g., b"\x81A" * runs) — that, when parsed, causes the library to expand data into arbitrarily large in-memory byte arrays without bound. The fix introduced a configurable constant RUN_LENGTH_MAX_OUTPUT_LENGTH (defaulting to 75 MB) and raises a LimitReachedError if the decompressed output exceeds this threshold (pypdf PR #3664, Patch Commit).
Successful exploitation causes a denial-of-service (DoS) condition by exhausting system memory on any host running a vulnerable pypdf version. Applications that accept and process user-supplied PDF files — such as document management systems, web services, or AI/ML pipelines — are at risk of crashing or becoming unresponsive. There is no impact on confidentiality or integrity; the vulnerability is limited to availability. IBM watsonx Orchestrate products that bundle pypdf are also affected (Github Advisory, IBM Advisory).
No public proof-of-concept exploit code has been published, and there is no evidence of in-the-wild exploitation at this time. The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it trivially exploitable against any internet-facing service that parses attacker-supplied PDFs with pypdf. The EPSS score is approximately 0.049% (0.000490), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory).
b"\x81A" * N where N is large enough to produce output exceeding 75 MB) followed by an EOD marker (b"\x80") to maximize memory expansion.RunLengthDecode.decode() method in pypdf/filters.py.MemoryError, out-of-memory (OOM) exceptions, or LimitReachedError (in patched versions) during PDF parsing operations; sudden process crashes or restarts correlated with PDF upload/processing events./var/log/syslog or dmesg on Linux systems.The primary remediation is to upgrade pypdf to version 6.7.4 or later, which introduces the RUN_LENGTH_MAX_OUTPUT_LENGTH constant (defaulting to 75 MB) to cap decompressed output size (pypdf Release 6.7.4). For deployments that cannot upgrade immediately, apply the changes from PR #3664 manually to add the output length limit to the RunLengthDecode.decode() method (pypdf PR #3664). Additional defensive measures include restricting PDF input to trusted sources only, setting OS-level memory limits on PDF processing processes, and monitoring applications for abnormal memory consumption patterns. IBM watsonx Orchestrate users should refer to the IBM advisories for product-specific patch guidance (IBM Advisory, IBM Advisory 2).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."