Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-84309Medium· 5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cyclic tree structure causes pypdf/generic/_data_structures.py TreeObject.insert_child to follow /Next links indefinitely when a …
CVE-2026-84311Medium· 5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_page.py PageObject._extract_text and PageObject.extract_xform_text to traverse a directed acyclic graph of reused fo…
CVE-2026-84310Medium· 5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consume long runtimes and large amounts of memory when retrieving document outlines wi…
CVE-2026-82398Medium· 5.3pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtimes when the pypdf/_utils.py function read_until_whitespace reads a stream containing a long run of bytes without…
CVE-2026-71870Mediumpypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumption when pypdf/_cmap.py function parse_bfrange parses unusually large source-code or destination-string tokens in a fo…
CVE-2026-71852Mediumpypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause long runtimes and large memory consumption when pypdf/_font.py function Font._collect_cid_character_widths expands unusually large CID font…
CVE-2026-59936Highpypdf: Possible infinite loop for not terminated inline images
CVE-2026-59935Highpypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
CVE-2026-59938Mediumpypdf: Possible large memory usage for wrong image dimensions
CVE-2026-59937Mediumpypdf: Possible long runtimes for repeated malformed cross-reference entries
CVE-2026-54651Mediumpypdf: Possible infinite loop when processing threads/articles in writer
CVE-2026-57204Mediumpypdf: Missing stream length values ignore defined limits
GHSA-jm82-fx9c-mx94Mediumpypdf: Missing stream length values ignore defined limits
CVE-2026-48735Mediumpypdf: Manipulated XMP metadata streams can exhaust RAM
CVE-2026-49460Mediumpypdf: Inefficient decoding of FlateDecode PNG predictor streams
CVE-2026-49461Mediumpypdf: Possible large memory usage for form XObjects during text extraction
CVE-2026-54530Mediumpypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction
CVE-2026-54531Mediumpypdf: Possible infinite loop when processing outlines/bookmarks in writer
CVE-2026-48155Mediumpypdf: Possible large memory usage for large offsets for layout mode text
CVE-2026-48156Low· 3.3pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streams
CVE-2026-41314Medium· 6.5pypdf: Manipulated FlateDecode image dimensions can exhaust RAM
CVE-2026-41312Medium· 6.5pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM
CVE-2026-41313Medium· 6.5pypdf: Possible long runtimes for wrong size values in incremental mode
CVE-2026-41168Medium· 5.3pypdf has long runtimes for wrong size values in cross-reference and object streams
CVE-2026-40260Medium· 5.3pypdf: Manipulated XMP metadata entity declarations can exhaust RAM
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.