Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-f2v5-7jq9-h8cg | pypdf: Manipulated RunLengthDecode streams can exhaust RAM |
Tue, 03 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 03 Mar 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pypdf Project
Pypdf Project pypdf |
|
| CPEs | cpe:2.3:a:pypdf_project:pypdf:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pypdf Project
Pypdf Project pypdf |
|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 03 Mar 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Mon, 02 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Py-pdf
Py-pdf pypdf |
|
| Vendors & Products |
Py-pdf
Py-pdf pypdf |
Fri, 27 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.4, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing the content stream using the RunLengthDecode filter. This has been fixed in pypdf 6.7.4. As a workaround, consider applying the changes from PR #3664. | |
| Title | Manipulated RunLengthDecode streams can exhaust RAM | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-03T20:28:45.592Z
Reserved: 2026-02-26T18:38:13.890Z
Link: CVE-2026-28351
Updated: 2026-03-03T20:28:41.738Z
Status : Analyzed
Published: 2026-02-27T21:16:19.177
Modified: 2026-03-03T18:36:06.290
Link: CVE-2026-28351
OpenCVE Enrichment
Updated: 2026-04-16T15:30:06Z
Github GHSA