Executive brief
pypdf: Manipulated FlateDecode XFA streams can exhaust RAM
Affected products
- PyPI pypdf
Junglewise Threat Intelligence
CVE-2026-27888 · Severity: medium · CVSS 4 · Published 2026-07-13
Technologies: pypdf (PyPI). Vendors: PyPI.
pypdf: Manipulated FlateDecode XFA streams can exhaust RAM