{"id":"CVE-2026-27628","title":"pypdf: possible infinite loop when loading circular /Prev entries in cross-reference streams (CVE-2026-27628)","summary":"A flaw was found in pypdf. Processing a specially crafted PDF document, specifically with circular /Prev references in the cross-reference (xref) chain, can cause an infinite loop and a high consumption of CPU, resulting in a denial of ser…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-835","vendor":"Red Hat","product":"Red Hat Quay 3.16","affected":["openshift_lightspeed","enterprise_linux_ai_rhel_ai 3","openshift_ai 2.25","quay 3.10","quay 3.12","quay 3.15","quay 3.16","quay 3.9"],"patched":["openshift_ai 2.25","quay 3.10","quay 3.12","quay 3.15","quay 3.16","quay 3.9"],"published":"2026-02-25","updated":"2026-09-09","sourceUpdated":"2026-09-09T22:38:01+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27628.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27628.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-27628"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2442543"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-27628"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27628"},{"url":"https://github.com/py-pdf/pypdf/commit/0fbd95938724ad2d72688d4112207c0590f0483f"},{"url":"https://github.com/py-pdf/pypdf/issues/3654"},{"url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-2rw7-x74f-jg35"},{"url":"https://access.redhat.com/errata/RHSA-2026:10184"},{"url":"https://access.redhat.com/errata/RHSA-2026:5665"},{"url":"https://access.redhat.com/errata/RHSA-2026:4942"},{"url":"https://access.redhat.com/errata/RHSA-2026:6568"},{"url":"https://access.redhat.com/errata/RHSA-2026:6497"},{"url":"https://access.redhat.com/errata/RHSA-2026:6567"},{"url":"https://access.redhat.com/errata/RHSA-2026:5168"},{"url":"https://github.com/py-pdf/pypdf/commit/f0a462d36971cf077d74492a348d0d06fd60ea4d"},{"url":"https://github.com/py-pdf/pypdf"}],"tags":["csaf","vex","red-hat","osv","pip"],"epss":0.00346,"epssPercentile":0.28215,"aliases":["GHSA-2rw7-x74f-jg35","PYSEC-2026-3005"],"ecosystem":"pip","ingestedAt":"2026-07-13T18:57:51.400Z","slug":"CVE-2026-27628","body":"## Overview\n\nA flaw was found in pypdf. Processing a specially crafted PDF document, specifically with circular /Prev references in the cross-reference (xref) chain, can cause an infinite loop and a high consumption of CPU, resulting in a denial of service.\n\n## Vendor advisories\n\n- **RHSA-2026:10184** · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-04-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:10184)\n- **RHSA-2026:5665** · Red Hat · fixed in: Red Hat Quay 3.10 · released 2026-03-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:5665)\n- **RHSA-2026:4942** · Red Hat · fixed in: Red Hat Quay 3.12 · released 2026-03-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:4942)\n- **RHSA-2026:6568** · Red Hat · fixed in: Red Hat Quay 3.15 · released 2026-04-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:6568)\n- **RHSA-2026:6497** · Red Hat · fixed in: Red Hat Quay 3.16 · released 2026-04-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:6497)\n- **RHSA-2026:6567** · Red Hat · fixed in: Red Hat Quay 3.16 · released 2026-04-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:6567)\n- **RHSA-2026:5168** · Red Hat · fixed in: Red Hat Quay 3.9 · released 2026-03-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:5168)\n- **Red Hat VEX** · Moderate · affected: OpenShift Lightspeed, Red Hat Enterprise Linux AI (RHEL AI) 3 · no fix planned: Red Hat Enterprise Linux AI (RHEL AI) 3, OpenShift Lightspeed · updated 2026-09-09 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27628.json)\n\n**pypdf: possible infinite loop when loading circular /Prev entries in cross-reference streams** — rated Moderate by Red Hat. Released 2026-02-25, updated 2026-09-09.\n\nAffected:\n\n- OpenShift Lightspeed\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n\nFixed:\n\n- Red Hat OpenShift AI 2.25\n- Red Hat Quay 3.10\n- Red Hat Quay 3.12\n- Red Hat Quay 3.15\n- Red Hat Quay 3.16\n- Red Hat Quay 3.9\n\nNo fix planned:\n\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- OpenShift Lightspeed\n\nNot affected:\n\n- Red Hat OpenShift AI 2.25\n- Red Hat Quay 3.10\n- Red Hat Quay 3.12\n- Red Hat Quay 3.15\n- Red Hat Quay 3.16\n- Red Hat Quay 3.9\n\n## Remediation\n\nFor Red Hat OpenShift AI 2.25.5 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:\n\nhttps://docs.redhat.com/en/documentation/red_hat_openshift_ai/ https://access.redhat.com/errata/RHSA-2026:10184\nBefore applying this update, make sure all previously released errata relevant\nto your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:5665\nBefore applying this update, make sure all previously released errata relevant\nto your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:4942\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.\n\n## Package advisory (CVE-2026-27628)\n\nAffected packages:\n\n- `pypdf < 6.7.2`\n\nPatched in:\n\n- `pypdf 6.7.2`\n\nSource: https://osv.dev/vulnerability/GHSA-2rw7-x74f-jg35","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":201486,"id":"CVE-2026-27628","ts":1789399510303,"field":"cvss","old":null,"new":"7.5"},{"seq":201485,"id":"CVE-2026-27628","ts":1789399510303,"field":"severity","old":"low","new":"high"},{"seq":200220,"id":"CVE-2026-27628","ts":1789397078949,"field":"cvss","old":"7.5","new":null},{"seq":200219,"id":"CVE-2026-27628","ts":1789397078949,"field":"severity","old":"high","new":"low"},{"seq":198144,"id":"CVE-2026-27628","ts":1789391727637,"field":"cvss","old":null,"new":"7.5"},{"seq":198143,"id":"CVE-2026-27628","ts":1789391727637,"field":"severity","old":"low","new":"high"},{"seq":195937,"id":"CVE-2026-27628","ts":1789383393047,"field":"cvss","old":"7.5","new":null},{"seq":195936,"id":"CVE-2026-27628","ts":1789383393047,"field":"severity","old":"high","new":"low"},{"seq":194866,"id":"CVE-2026-27628","ts":1789380298751,"field":"cvss","old":null,"new":"7.5"},{"seq":194865,"id":"CVE-2026-27628","ts":1789380298751,"field":"severity","old":"low","new":"high"},{"seq":193653,"id":"CVE-2026-27628","ts":1789378261878,"field":"cvss","old":"7.5","new":null},{"seq":193652,"id":"CVE-2026-27628","ts":1789378261878,"field":"severity","old":"high","new":"low"},{"seq":192440,"id":"CVE-2026-27628","ts":1789376228707,"field":"cvss","old":null,"new":"7.5"},{"seq":192439,"id":"CVE-2026-27628","ts":1789376228707,"field":"severity","old":"low","new":"high"},{"seq":191227,"id":"CVE-2026-27628","ts":1789373119465,"field":"cvss","old":"7.5","new":null},{"seq":191226,"id":"CVE-2026-27628","ts":1789373119465,"field":"severity","old":"high","new":"low"},{"seq":190012,"id":"CVE-2026-27628","ts":1789369119654,"field":"cvss","old":null,"new":"7.5"},{"seq":190011,"id":"CVE-2026-27628","ts":1789369119654,"field":"severity","old":"low","new":"high"},{"seq":188799,"id":"CVE-2026-27628","ts":1789368035192,"field":"cvss","old":"7.5","new":null},{"seq":188798,"id":"CVE-2026-27628","ts":1789368035192,"field":"severity","old":"high","new":"low"},{"seq":187582,"id":"CVE-2026-27628","ts":1789364989828,"field":"cvss","old":null,"new":"7.5"},{"seq":187581,"id":"CVE-2026-27628","ts":1789364989828,"field":"severity","old":"low","new":"high"},{"seq":186369,"id":"CVE-2026-27628","ts":1789362995763,"field":"cvss","old":"7.5","new":null},{"seq":186368,"id":"CVE-2026-27628","ts":1789362995763,"field":"severity","old":"high","new":"low"},{"seq":185155,"id":"CVE-2026-27628","ts":1789360961934,"field":"cvss","old":null,"new":"7.5"},{"seq":185154,"id":"CVE-2026-27628","ts":1789360961934,"field":"severity","old":"low","new":"high"},{"seq":183942,"id":"CVE-2026-27628","ts":1789357936880,"field":"cvss","old":"7.5","new":null},{"seq":183941,"id":"CVE-2026-27628","ts":1789357936880,"field":"severity","old":"high","new":"low"},{"seq":182194,"id":"CVE-2026-27628","ts":1789354089301,"field":"cvss","old":null,"new":"7.5"},{"seq":182193,"id":"CVE-2026-27628","ts":1789354089301,"field":"severity","old":"low","new":"high"},{"seq":180987,"id":"CVE-2026-27628","ts":1789352936675,"field":"cvss","old":"7.5","new":null},{"seq":180986,"id":"CVE-2026-27628","ts":1789352936675,"field":"severity","old":"high","new":"low"},{"seq":179780,"id":"CVE-2026-27628","ts":1789349989617,"field":"cvss","old":null,"new":"7.5"},{"seq":179779,"id":"CVE-2026-27628","ts":1789349989617,"field":"severity","old":"low","new":"high"},{"seq":178573,"id":"CVE-2026-27628","ts":1789347804071,"field":"cvss","old":"7.5","new":null},{"seq":178572,"id":"CVE-2026-27628","ts":1789347804071,"field":"severity","old":"high","new":"low"},{"seq":177366,"id":"CVE-2026-27628","ts":1789346171365,"field":"cvss","old":null,"new":"7.5"},{"seq":177365,"id":"CVE-2026-27628","ts":1789346171365,"field":"severity","old":"low","new":"high"},{"seq":176159,"id":"CVE-2026-27628","ts":1789342744402,"field":"cvss","old":"7.5","new":null},{"seq":176158,"id":"CVE-2026-27628","ts":1789342744402,"field":"severity","old":"high","new":"low"},{"seq":175943,"id":"CVE-2026-27628","ts":1789342351313,"field":"cvss","old":null,"new":"7.5"},{"seq":175942,"id":"CVE-2026-27628","ts":1789342351313,"field":"severity","old":"low","new":"high"},{"seq":175483,"id":"CVE-2026-27628","ts":1789338382514,"field":"cvss","old":"7.5","new":null},{"seq":175482,"id":"CVE-2026-27628","ts":1789338382514,"field":"severity","old":"high","new":"low"},{"seq":174278,"id":"CVE-2026-27628","ts":1789334592140,"field":"cvss","old":null,"new":"7.5"},{"seq":174277,"id":"CVE-2026-27628","ts":1789334592140,"field":"severity","old":"low","new":"high"},{"seq":173073,"id":"CVE-2026-27628","ts":1789333196830,"field":"cvss","old":"7.5","new":null},{"seq":173072,"id":"CVE-2026-27628","ts":1789333196830,"field":"severity","old":"high","new":"low"},{"seq":171887,"id":"CVE-2026-27628","ts":1789330876250,"field":"cvss","old":null,"new":"7.5"},{"seq":171886,"id":"CVE-2026-27628","ts":1789330876250,"field":"severity","old":"low","new":"high"}]}