VulnSea

pypdf_project has 8 CVEs on record. Disclosure cadence is accelerating: 8 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 8. The median CVSS is 7.5 (high). None have a confirmed exploitation report. The dominant weakness classes are CWE-400 (8) and CWE-770 (4).

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
—
Last 90 days
8 prev 0

Products

  • pypdf 8
8
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

pypdf_project vulnerabilities

CVEs affecting pypdf_project, newest first. Open any entry for full detail, references, and exploit status.

8 CVEsRSS

CVE-2026-103000High· 7.5
5d ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF can provide unusually large alphabetical page-label values that cause pypdf/_page_labels.py to generate strings beyond a reasonable page-label length…

▾ Twilightpypdf_project · pypdfEPSS 0.30%via NVD
CVE-2026-102999High· 7.5
5d ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF containing many embedded files can cause the dictionary-based attachments API in pypdf/_doc_common.py to reparse the full attachment list for each co…

▾ Twilightpypdf_project · pypdfEPSS 0.30%via NVD
CVE-2026-102998High· 7.5
5d ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF with form field values can cause pypdf/generic/_appearance_stream.py appearance-stream generation to repeat invariant selection-data work inside a lo…

▾ Twilightpypdf_project · pypdfEPSS 0.30%via NVD
CVE-2026-102997High· 7.5
5d ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF containing a partially malformed /FlateDecode stream with padded data can force pypdf/filters.py to use inefficient byte-by-byte decompression while …

▾ Twilightpypdf_project · pypdfEPSS 0.30%via NVD
CVE-2026-102996High· 7.5
5d ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can provide a TrueType or Type1 simple font with an unusually large /Widths array, causing pypdf/_font.py Font._collect_tt_t1_character_widths to pro…

▾ Twilightpypdf_project · pypdfEPSS 0.30%via NVD
CVE-2026-102995High· 7.5⚖ disputed
5d ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can place unusually large source-code or destination-string tokens in a font /ToUnicode mapping, causing pypdf/_cmap.py parse_bfchar to decode and re…

▾ Twilightpypdf_project · pypdfEPSS 0.30%via NVD
CVE-2026-102994High· 7.5
5d ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.18.0, a crafted PDF containing indirect-object identifiers or generation-number tokens that continue for a long time without whitespace can cause pypdf/_reader.py and py…

▾ Twilightpypdf_project · pypdfEPSS 0.30%via NVD
CVE-2026-102993High· 7.5⚖ disputed
5d ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an applicatio…

▾ Twilightpypdf_project · pypdfEPSS 0.35%via NVD
pypdf_project vulnerabilities (CVEs) · VulnSea