---
id: CVE-2026-27628
title: >-
  pypdf: possible infinite loop when loading circular /Prev entries in
  cross-reference streams (CVE-2026-27628)
summary: >-
  A flaw was found in pypdf. Processing a specially crafted PDF document,
  specifically with circular /Prev references in the cross-reference (xref)
  chain, can cause an infinite loop and a high consumption of CPU, resulting in
  a denial of ser…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-835
vendor: Red Hat
product: Red Hat Quay 3.16
affected:
  - openshift_lightspeed
  - enterprise_linux_ai_rhel_ai 3
  - openshift_ai 2.25
  - quay 3.10
  - quay 3.12
  - quay 3.15
  - quay 3.16
  - quay 3.9
patched:
  - openshift_ai 2.25
  - quay 3.10
  - quay 3.12
  - quay 3.15
  - quay 3.16
  - quay 3.9
published: '2026-02-25'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T22:38:01+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27628.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27628.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-27628'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2442543'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-27628'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-27628'
  - url: >-
      https://github.com/py-pdf/pypdf/commit/0fbd95938724ad2d72688d4112207c0590f0483f
  - url: 'https://github.com/py-pdf/pypdf/issues/3654'
  - url: 'https://github.com/py-pdf/pypdf/security/advisories/GHSA-2rw7-x74f-jg35'
  - url: 'https://access.redhat.com/errata/RHSA-2026:10184'
  - url: 'https://access.redhat.com/errata/RHSA-2026:5665'
  - url: 'https://access.redhat.com/errata/RHSA-2026:4942'
  - url: 'https://access.redhat.com/errata/RHSA-2026:6568'
  - url: 'https://access.redhat.com/errata/RHSA-2026:6497'
  - url: 'https://access.redhat.com/errata/RHSA-2026:6567'
  - url: 'https://access.redhat.com/errata/RHSA-2026:5168'
  - url: >-
      https://github.com/py-pdf/pypdf/commit/f0a462d36971cf077d74492a348d0d06fd60ea4d
  - url: 'https://github.com/py-pdf/pypdf'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
epss: 0.00346
epssPercentile: 0.28218
aliases:
  - GHSA-2rw7-x74f-jg35
  - PYSEC-2026-3005
ecosystem: pip
ingestedAt: '2026-07-13T18:57:51.400Z'
---

## Overview

A flaw was found in pypdf. Processing a specially crafted PDF document, specifically with circular /Prev references in the cross-reference (xref) chain, can cause an infinite loop and a high consumption of CPU, resulting in a denial of service.

## Vendor advisories

- **RHSA-2026:10184** · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-04-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:10184)
- **RHSA-2026:5665** · Red Hat · fixed in: Red Hat Quay 3.10 · released 2026-03-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:5665)
- **RHSA-2026:4942** · Red Hat · fixed in: Red Hat Quay 3.12 · released 2026-03-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:4942)
- **RHSA-2026:6568** · Red Hat · fixed in: Red Hat Quay 3.15 · released 2026-04-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:6568)
- **RHSA-2026:6497** · Red Hat · fixed in: Red Hat Quay 3.16 · released 2026-04-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:6497)
- **RHSA-2026:6567** · Red Hat · fixed in: Red Hat Quay 3.16 · released 2026-04-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:6567)
- **RHSA-2026:5168** · Red Hat · fixed in: Red Hat Quay 3.9 · released 2026-03-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:5168)
- **Red Hat VEX** · Moderate · affected: OpenShift Lightspeed, Red Hat Enterprise Linux AI (RHEL AI) 3 · no fix planned: Red Hat Enterprise Linux AI (RHEL AI) 3, OpenShift Lightspeed · updated 2026-09-09 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27628.json)

**pypdf: possible infinite loop when loading circular /Prev entries in cross-reference streams** — rated Moderate by Red Hat. Released 2026-02-25, updated 2026-09-09.

Affected:

- OpenShift Lightspeed
- Red Hat Enterprise Linux AI (RHEL AI) 3

Fixed:

- Red Hat OpenShift AI 2.25
- Red Hat Quay 3.10
- Red Hat Quay 3.12
- Red Hat Quay 3.15
- Red Hat Quay 3.16
- Red Hat Quay 3.9

No fix planned:

- Red Hat Enterprise Linux AI (RHEL AI) 3
- OpenShift Lightspeed

Not affected:

- Red Hat OpenShift AI 2.25
- Red Hat Quay 3.10
- Red Hat Quay 3.12
- Red Hat Quay 3.15
- Red Hat Quay 3.16
- Red Hat Quay 3.9

## Remediation

For Red Hat OpenShift AI 2.25.5 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:

https://docs.redhat.com/en/documentation/red_hat_openshift_ai/ https://access.redhat.com/errata/RHSA-2026:10184
Before applying this update, make sure all previously released errata relevant
to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:5665
Before applying this update, make sure all previously released errata relevant
to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:4942

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

## Package advisory (CVE-2026-27628)

Affected packages:

- `pypdf < 6.7.2`

Patched in:

- `pypdf 6.7.2`

Source: https://osv.dev/vulnerability/GHSA-2rw7-x74f-jg35
