VulnSea

pypdf vulnerabilities

CVEs whose affected-version data names the pypdf package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

43 CVEsRSS

CVE-2026-84309Medium
3w ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cyclic tree structure causes pypdf/generic/_data_structures.py TreeObject.insert_child to follow /Next links indefinitely when a …

Sunlitpypdf · pypdfEPSS 0.13%via NVD
CVE-2026-84311Medium
3w ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_page.py PageObject._extract_text and PageObject.extract_xform_text to traverse a directed acyclic graph of reused fo…

Sunlitpypdf · pypdfEPSS 0.14%via NVD
CVE-2026-84310Medium
3w ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consume long runtimes and large amounts of memory when retrieving document outlines wi…

Sunlitpypdf · pypdfEPSS 0.14%via NVD
CVE-2026-82398Medium
3w ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtimes when the pypdf/_utils.py function read_until_whitespace reads a stream containing a long run of bytes without…

Sunlitpypdf · pypdfEPSS 0.30%via NVD
CVE-2026-71870Medium
1mo ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumption when pypdf/_cmap.py function parse_bfrange parses unusually large source-code or destination-string tokens in a fo…

Sunlitpypdf · pypdfEPSS 0.13%via NVD
CVE-2026-71852Medium
1mo ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause long runtimes and large memory consumption when pypdf/_font.py function Font._collect_cid_character_widths expands unusually large CID font…

Sunlitpypdf · pypdfEPSS 0.13%via NVD
CVE-2026-59936High
2mo ago

pypdf: Possible infinite loop for not terminated inline images

pypdf: Possible infinite loop for not terminated inline images

Twilightpypdf · pypdfEPSS 0.34%via OSV
CVE-2026-59935High
2mo ago

pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)

pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)

Twilightpypdf · pypdfEPSS 0.62%via OSV
CVE-2026-59938Medium
2mo ago

pypdf: Possible large memory usage for wrong image dimensions

pypdf: Possible large memory usage for wrong image dimensions

Sunlitpypdf · pypdfEPSS 0.52%via OSV
CVE-2026-59937Medium
2mo ago

pypdf: Possible long runtimes for repeated malformed cross-reference entries

pypdf: Possible long runtimes for repeated malformed cross-reference entries

Sunlitpypdf · pypdfEPSS 0.34%via OSV
CVE-2026-54651Medium
2mo ago

pypdf: Possible infinite loop when processing threads/articles in writer

pypdf: Possible infinite loop when processing threads/articles in writer

Sunlitpypdf · pypdfEPSS 0.16%via GHSA
CVE-2026-57204Medium
3mo ago

pypdf: Missing stream length values ignore defined limits

pypdf: Missing stream length values ignore defined limits

Sunlitpypdf · pypdfEPSS 0.37%via OSV
GHSA-jm82-fx9c-mx94Medium
3mo ago

pypdf: Missing stream length values ignore defined limits

pypdf: Missing stream length values ignore defined limits

Sunlitpypdf · pypdfvia GHSA
CVE-2026-48735Medium
3mo ago

pypdf: Manipulated XMP metadata streams can exhaust RAM

pypdf: Manipulated XMP metadata streams can exhaust RAM

Sunlitpypdf · pypdfEPSS 0.13%via GHSA
CVE-2026-49460Medium
3mo ago

pypdf: Inefficient decoding of FlateDecode PNG predictor streams

pypdf: Inefficient decoding of FlateDecode PNG predictor streams

Sunlitpypdf · pypdfEPSS 0.17%via GHSA
CVE-2026-49461Medium
3mo ago

pypdf: Possible large memory usage for form XObjects during text extraction

pypdf: Possible large memory usage for form XObjects during text extraction

Sunlitpypdf · pypdfEPSS 0.17%via GHSA
CVE-2026-54530Medium
3mo ago

pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction

pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction

Sunlitpypdf · pypdfEPSS 0.17%via OSV
CVE-2026-54531Medium
3mo ago

pypdf: Possible infinite loop when processing outlines/bookmarks in writer

pypdf: Possible infinite loop when processing outlines/bookmarks in writer

Sunlitpypdf · pypdfEPSS 0.17%via OSV
CVE-2026-48155Medium
3mo ago

pypdf: Possible large memory usage for large offsets for layout mode text

pypdf: Possible large memory usage for large offsets for layout mode text

Sunlitpypdf · pypdfEPSS 0.13%via OSV
CVE-2026-48156Low· 3.3
3mo ago

pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference …

pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streams

Sunlitpypdf · pypdfEPSS 0.12%via OSV
CVE-2026-41314Medium· 6.5
5mo ago

pypdf: Manipulated FlateDecode image dimensions can exhaust RAM

pypdf: Manipulated FlateDecode image dimensions can exhaust RAM

Sunlitpypdf · pypdfEPSS 0.23%via OSV
CVE-2026-41312Medium· 6.5
5mo ago

pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM

pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM

Sunlitpypdf · pypdfEPSS 0.23%via OSV
CVE-2026-41313Medium· 6.5
5mo ago

pypdf: Possible long runtimes for wrong size values in incremental mode

pypdf: Possible long runtimes for wrong size values in incremental mode

Sunlitpypdf · pypdfEPSS 0.21%via OSV
CVE-2026-41168Medium· 5.3
5mo ago

pypdf has long runtimes for wrong size values in cross-reference and object streams

pypdf has long runtimes for wrong size values in cross-reference and object streams

Sunlitpypdf · pypdfEPSS 0.30%via OSV
CVE-2026-40260Medium· 5.3
5mo ago

pypdf: Manipulated XMP metadata entity declarations can exhaust RAM

pypdf: Manipulated XMP metadata entity declarations can exhaust RAM

Sunlitpypdf · pypdfEPSS 0.42%via OSV
CVE-2026-33699Medium
6mo ago

pypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_stream

pypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_stream

Sunlitpypdf · pypdfEPSS 0.46%via OSV
CVE-2026-33123Medium
6mo ago

pypdf has inefficient decoding of array-based streams

pypdf has inefficient decoding of array-based streams

Sunlitpypdf · pypdfEPSS 0.35%via OSV
CVE-2026-31826Medium
6mo ago

pypdf: manipulated stream length values can exhaust RAM

pypdf: manipulated stream length values can exhaust RAM

Sunlitpypdf · pypdfEPSS 0.17%via OSV
CVE-2026-28804Medium
6mo ago

pypdf vulnerable to inefficient decoding of ASCIIHexDecode streams

pypdf vulnerable to inefficient decoding of ASCIIHexDecode streams

Sunlitpypdf · pypdfEPSS 0.40%via OSV
CVE-2026-28351Medium
6mo ago

pypdf: Manipulated RunLengthDecode streams can exhaust RAM

pypdf: Manipulated RunLengthDecode streams can exhaust RAM

Sunlitpypdf · pypdfEPSS 0.42%via OSV
pypdf vulnerabilities (CVEs) · VulnSea