Логотип exploitDog
bind:"CVE-2026-27888"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2026-27888"

Количество 7

Количество 7

ubuntu логотип

CVE-2026-27888

30 дней назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.3, an attacker who uses this vulnerability can craft a PDF which leads to the RAM being exhausted. This requires accessing the `xfa` property of a reader or writer and the corresponding stream being compressed using `/FlateDecode`. This has been fixed in pypdf 6.7.3. As a workaround, apply the patch manually.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-27888

30 дней назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.3, an attacker who uses this vulnerability can craft a PDF which leads to the RAM being exhausted. This requires accessing the `xfa` property of a reader or writer and the corresponding stream being compressed using `/FlateDecode`. This has been fixed in pypdf 6.7.3. As a workaround, apply the patch manually.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-27888

30 дней назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.3, an attacker who uses this vulnerability can craft a PDF which leads to the RAM being exhausted. This requires accessing the `xfa` property of a reader or writer and the corresponding stream being compressed using `/FlateDecode`. This has been fixed in pypdf 6.7.3. As a workaround, apply the patch manually.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-27888

30 дней назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.7. ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-x7hp-r3qg-r3cj

29 дней назад

pypdf: Manipulated FlateDecode XFA streams can exhaust RAM

EPSS: Низкий
fstec логотип

BDU:2026-02549

около 1 месяца назад

Уязвимость библиотеки Python для работы с PDF файлами PyPDF, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20333-1

21 день назад

Security update for python-PyPDF2

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-27888

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.3, an attacker who uses this vulnerability can craft a PDF which leads to the RAM being exhausted. This requires accessing the `xfa` property of a reader or writer and the corresponding stream being compressed using `/FlateDecode`. This has been fixed in pypdf 6.7.3. As a workaround, apply the patch manually.

CVSS3: 7.5
0%
Низкий
30 дней назад
redhat логотип
CVE-2026-27888

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.3, an attacker who uses this vulnerability can craft a PDF which leads to the RAM being exhausted. This requires accessing the `xfa` property of a reader or writer and the corresponding stream being compressed using `/FlateDecode`. This has been fixed in pypdf 6.7.3. As a workaround, apply the patch manually.

CVSS3: 5.3
0%
Низкий
30 дней назад
nvd логотип
CVE-2026-27888

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.3, an attacker who uses this vulnerability can craft a PDF which leads to the RAM being exhausted. This requires accessing the `xfa` property of a reader or writer and the corresponding stream being compressed using `/FlateDecode`. This has been fixed in pypdf 6.7.3. As a workaround, apply the patch manually.

CVSS3: 7.5
0%
Низкий
30 дней назад
debian логотип
CVE-2026-27888

pypdf is a free and open-source pure-python PDF library. Prior to 6.7. ...

CVSS3: 7.5
0%
Низкий
30 дней назад
github логотип
GHSA-x7hp-r3qg-r3cj

pypdf: Manipulated FlateDecode XFA streams can exhaust RAM

0%
Низкий
29 дней назад
fstec логотип
BDU:2026-02549

Уязвимость библиотеки Python для работы с PDF файлами PyPDF, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20333-1

Security update for python-PyPDF2

21 день назад

Уязвимостей на страницу