6.9

CVSS4.0

CVE-2026-27026 - pypdf possibly has long runtimes for malformed FlateDecode streams

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires a malformed /FlateDecode stream, where the byte-by-byte decompression is used. This vulnerability is fixed in 6.7.1.

๐Ÿ“… Published: Feb. 20, 2026, 9:12 p.m. ๐Ÿ”„ Last Modified: Feb. 20, 2026, 9:12 p.m.

6.9

CVSS4.0

CVE-2026-27025 - pypdf has possible long runtimes/large memory usage for large /ToUnicode streams

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes and large memory consumption. This requires parsing the /ToUnicode entry of a font with unusually large values, for example during text extraโ€ฆ

๐Ÿ“… Published: Feb. 20, 2026, 9:11 p.m. ๐Ÿ”„ Last Modified: Feb. 20, 2026, 9:11 p.m.

6.9

CVSS4.0

CVE-2026-27024 - pypdf has a possible infinite loop when processing TreeObject

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires accessing the children of a TreeObject, for example as part of outlines. This vulnerability is fixed in 6.7.1.

๐Ÿ“… Published: Feb. 20, 2026, 9:10 p.m. ๐Ÿ”„ Last Modified: Feb. 20, 2026, 9:10 p.m.

6.5

CVSS3.1

CVE-2026-27022 - RediSearch Query Injection in @langchain/langgraph-checkpoint-redis

@langchain/langgraph-checkpoint-redis is the Redis checkpoint and store implementation for LangGraph. A query injection vulnerability exists in the @langchain/langgraph-checkpoint-redis package's filter handling. The RedisSaver and ShallowRedisSaver classes construct RediSearch queries by directly โ€ฆ

๐Ÿ“… Published: Feb. 20, 2026, 9:06 p.m. ๐Ÿ”„ Last Modified: Feb. 20, 2026, 9:06 p.m.

5.3

CVSS4.0

CVE-2026-27020 - Photobooth has a XSS vulnerability in user input

Photobooth prior to 1.0.1 has a cross-site scripting (XSS) vulnerability in user input fields. Malicious users could inject scripts through unvalidated form inputs. This vulnerability is fixed in 1.0.1.

๐Ÿ“… Published: Feb. 20, 2026, 9:03 p.m. ๐Ÿ”„ Last Modified: Feb. 20, 2026, 9:19 p.m.
Load More Vulnerability
avatar

Mehmet Ince

@mdisec

CVE stats coming here

avatar

Nuri ร‡ilengir

@ncilengir

CVE stats coming here

avatar

@aydinnyunus

CVE stats coming here

avatar

Onurcan Genรง

@onurcangnc

CVE stats coming here

avatar

Seyit Sigirci

@h3xecute

CVE stats coming here

avatar

Ali ฤฐltizar

@iltosec

CVE stats coming here

avatar

@b3rsec

CVE stats coming here

avatar

@furkank

CVE stats coming here

avatar

kutaysec

@kutaysec

CVE stats coming here