CVE-2026-27628Disclosure(pypdf_project / pypdf)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.2, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires reading the file. This has been fixed in pypdf 6.7.2. As a workaround, one may apply the patch manually.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-835

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pypdf

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-02-25); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Products
pypdf

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-25: 3Mentions · 2026-03-02: 1Technical Details · 2026-02-25: 3Technical Details · 2026-03-02: 102-2503-02
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-253
Disclosure3
2026-03-021
Disclosure1
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27628 Infinite Loop Vulnerability in pypdf Library Before Version 6.7.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27628

    Post summary

    A new infinite loop vulnerability (CVE-2026-27628) affecting pypdf library versions before 6.7.2 has been disclosed, with details available on Vulmon.

    0001035
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-27628 (CVSS:1.2, HIGH) is Modified. pypdf is a free and open-source pure-python PDF library. Prior to 6.7.2, an attacker who uses this vulnerability can cra..https://nvd.nist.gov/vuln/detail/CVE-2026-27628 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-27628, a high‑severity vulnerability in pypdf before version 6.7.2, providing basic technical details but no PoC, exploit code, or patch information.

    0000039
    173 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27628: The Ouroboros Document: Infinite Loops in pypdf A critical Denial of Service (DoS) vulnerability exists in the `pypdf` library, a ubiquitous tool for PDF manipulation in the Python ecosystem. By crafting a PDF with a circular cross-ref... https://cvereports.com/reports/CVE-2026-27628

    Post summary

    The post announces a critical DoS vulnerability in the pypdf library caused by circular cross‑references in PDFs, but provides no PoC, exploit, patch, or evidence of active exploitation.

    0000033
    31 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27628 pypdf is a free and open-source pure-python PDF library. Prior to 6.7.2, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This… https://www.cve.org/CVERecord?id=CVE-2026-27628

    Post summary

    The post announces CVE‑2026‑27628 in the pypdf library, noting that before version 6.7.2 a crafted PDF can trigger an infinite loop, but it does not provide a PoC, exploit, patch, or evidence of active exploitation.

    00000276
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppypdf_projectpypdf---

Explore more