pypdf vulnerabilities
CVEs whose affected-version data names the pypdf package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
43 CVEsRSS
CVE-2026-27888Mediumpypdf: Manipulated FlateDecode XFA streams can exhaust RAM
pypdf: Manipulated FlateDecode XFA streams can exhaust RAM
CVE-2026-27025Mediumpypdf has possible long runtimes/large memory usage for large /ToUnicode streams
pypdf has possible long runtimes/large memory usage for large /ToUnicode streams
CVE-2026-27026Mediumpypdf possibly has long runtimes for malformed FlateDecode streams
pypdf possibly has long runtimes for malformed FlateDecode streams
CVE-2026-27024Mediumpypdf has a possible infinite loop when processing TreeObject
pypdf has a possible infinite loop when processing TreeObject
CVE-2026-24688MediumPoCpypdf has possible Infinite Loop when processing outlines/bookmarks
pypdf has possible Infinite Loop when processing outlines/bookmarks
CVE-2026-22690Lowpypdf has possible long runtimes for missing /Root object with large /Size values
pypdf has possible long runtimes for missing /Root object with large /Size values
CVE-2026-22691Lowpypdf has possible long runtimes for malformed startxref
pypdf has possible long runtimes for malformed startxref
CVE-2025-66019Mediumpypdf's LZWDecode streams be manipulated to exhaust RAM
pypdf's LZWDecode streams be manipulated to exhaust RAM
CVE-2025-62707Mediumpypdf possibly loops infinitely when reading DCT inline images without EOF marker
pypdf possibly loops infinitely when reading DCT inline images without EOF marker
CVE-2025-62708Mediumpypdf can exhaust RAM via manipulated LZWDecode streams
pypdf can exhaust RAM via manipulated LZWDecode streams
CVE-2025-55197MediumPyPDF's Manipulated FlateDecode streams can exhaust RAM
PyPDF's Manipulated FlateDecode streams can exhaust RAM
CVE-2023-46250Medium· 5.1Possible Infinite Loop when PdfWriter(clone_from) is used with a PDF
Possible Infinite Loop when PdfWriter(clone_from) is used with a PDF
CVE-2023-36464Medium· 6.2pypdf and PyPDF2 possible Infinite Loop when a comment isn't followed by a character
pypdf and PyPDF2 possible Infinite Loop when a comment isn't followed by a character