CVE-2026-27888
pypdf is a free and open-source pure-python PDF library. Prior to 6.7.3, an attacker who uses this vulnerability can cra
pypdf is a free and open-source pure-python PDF library. Prior to 6.7.3, an attacker who uses this vulnerability can craft a PDF which leads to the RAM being exhausted. This requires accessing the xfa property of a reader or writer and the corresponding stream being compressed using /FlateDecode.
This has been fixed in pypdf 6.7.3. As a workaround, apply the patch manually.
HIGH · CVSS 7.5
EPSS 0.00055
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0