pypdf vulnerabilities
CVEs whose affected-version data names the pypdf package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
43 CVEsRSS
CVE-2026-84309Mediumpypdf is a free and open-source pure-python PDF library
pypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cyclic tree structure causes pypdf/generic/_data_structures.py TreeObject.insert_child to follow /Next links indefinitely when a …
CVE-2026-84311Mediumpypdf is a free and open-source pure-python PDF library
pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_page.py PageObject._extract_text and PageObject.extract_xform_text to traverse a directed acyclic graph of reused fo…
CVE-2026-84310Mediumpypdf is a free and open-source pure-python PDF library
pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consume long runtimes and large amounts of memory when retrieving document outlines wi…
CVE-2026-82398Mediumpypdf is a free and open-source pure-python PDF library
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtimes when the pypdf/_utils.py function read_until_whitespace reads a stream containing a long run of bytes without…
CVE-2026-71870Mediumpypdf is a free and open-source pure-python PDF library
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumption when pypdf/_cmap.py function parse_bfrange parses unusually large source-code or destination-string tokens in a fo…
CVE-2026-71852Mediumpypdf is a free and open-source pure-python PDF library
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause long runtimes and large memory consumption when pypdf/_font.py function Font._collect_cid_character_widths expands unusually large CID font…
CVE-2026-59936Highpypdf: Possible infinite loop for not terminated inline images
pypdf: Possible infinite loop for not terminated inline images
CVE-2026-59935Highpypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
CVE-2026-59938Mediumpypdf: Possible large memory usage for wrong image dimensions
pypdf: Possible large memory usage for wrong image dimensions
CVE-2026-59937Mediumpypdf: Possible long runtimes for repeated malformed cross-reference entries
pypdf: Possible long runtimes for repeated malformed cross-reference entries
CVE-2026-54651Mediumpypdf: Possible infinite loop when processing threads/articles in writer
pypdf: Possible infinite loop when processing threads/articles in writer
CVE-2026-57204Mediumpypdf: Missing stream length values ignore defined limits
pypdf: Missing stream length values ignore defined limits
GHSA-jm82-fx9c-mx94Mediumpypdf: Missing stream length values ignore defined limits
pypdf: Missing stream length values ignore defined limits
CVE-2026-48735Mediumpypdf: Manipulated XMP metadata streams can exhaust RAM
pypdf: Manipulated XMP metadata streams can exhaust RAM
CVE-2026-49460Mediumpypdf: Inefficient decoding of FlateDecode PNG predictor streams
pypdf: Inefficient decoding of FlateDecode PNG predictor streams
CVE-2026-49461Mediumpypdf: Possible large memory usage for form XObjects during text extraction
pypdf: Possible large memory usage for form XObjects during text extraction
CVE-2026-54530Mediumpypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction
pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction
CVE-2026-54531Mediumpypdf: Possible infinite loop when processing outlines/bookmarks in writer
pypdf: Possible infinite loop when processing outlines/bookmarks in writer
CVE-2026-48155Mediumpypdf: Possible large memory usage for large offsets for layout mode text
pypdf: Possible large memory usage for large offsets for layout mode text
CVE-2026-48156Low· 3.3pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference …
pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streams
CVE-2026-41314Medium· 6.5pypdf: Manipulated FlateDecode image dimensions can exhaust RAM
pypdf: Manipulated FlateDecode image dimensions can exhaust RAM
CVE-2026-41312Medium· 6.5pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM
pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM
CVE-2026-41313Medium· 6.5pypdf: Possible long runtimes for wrong size values in incremental mode
pypdf: Possible long runtimes for wrong size values in incremental mode
CVE-2026-41168Medium· 5.3pypdf has long runtimes for wrong size values in cross-reference and object streams
pypdf has long runtimes for wrong size values in cross-reference and object streams
CVE-2026-40260Medium· 5.3pypdf: Manipulated XMP metadata entity declarations can exhaust RAM
pypdf: Manipulated XMP metadata entity declarations can exhaust RAM
CVE-2026-33699Mediumpypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_stream
pypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_stream
CVE-2026-33123Mediumpypdf has inefficient decoding of array-based streams
pypdf has inefficient decoding of array-based streams
CVE-2026-31826Mediumpypdf: manipulated stream length values can exhaust RAM
pypdf: manipulated stream length values can exhaust RAM
CVE-2026-28804Mediumpypdf vulnerable to inefficient decoding of ASCIIHexDecode streams
pypdf vulnerable to inefficient decoding of ASCIIHexDecode streams
CVE-2026-28351Mediumpypdf: Manipulated RunLengthDecode streams can exhaust RAM
pypdf: Manipulated RunLengthDecode streams can exhaust RAM