Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

pypdf — Vulnerabilities & Security Advisories 41

All 41 CVE vulnerabilities found in pypdf, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumeration (CWE) vulnerabilities associated with the pypdf Python library, categorized under the Python ecosystem and security software tags. It collects a comprehensive range of security defects, including buffer overflows, injection flaws, and improper input validation issues, covering publicly disclosed incidents from 2020 to the present. Visitors can utilize this resource to track vendor advisories and update notifications from the pypdf development team, gaining insight into how the maintainers address and mitigate reported security risks. Furthermore, the page allows users to understand specific weakness classes by examining their manifestation within this particular codebase, facilitating a deeper comprehension of common Python library vulnerabilities. By reviewing the historical data, developers and security analysts can look up the vulnerability history of pypdf, identifying trends in code quality over time and understanding the cumulative impact of past exploits. This structured overview serves as a vital reference for assessing the security posture of applications relying on pypdf, helping teams prioritize patches and implement effective defense strategies against known threats in the supply chain.

Vendor: py-pdf

CVE IDTitleCVSSSeverityPublished
CVE-2026-71870 pypdf: Possible large memory usage for large /ToUnicode streams CWE-400 4.8 Medium2026-08-07
CVE-2026-71852 pypdf: Possible long runtimes/large memory usage for large CID font width ranges CWE-834 4.8 Medium2026-08-07
CVE-2026-59936 pypdf: Possible infinite loop for not terminated inline images CWE-400--2026-07-08
CVE-2026-59935 pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter) CWE-835--2026-07-08
CVE-2026-59937 pypdf: Possible long runtimes for repeated malformed cross-reference entries CWE-400--2026-07-08
CVE-2026-59938 pypdf: Possible large memory usage for wrong image dimensions CWE-789--2026-07-08
CVE-2026-57204 pypdf: Missing stream length values ignore defined limits CWE-400--2026-06-30
CVE-2026-54651 pypdf: Possible infinite loop when processing threads/articles in writer CWE-835--2026-06-22
CVE-2026-49460 pypdf: Inefficient decoding of FlateDecode PNG predictor streams CWE-407--2026-06-22
CVE-2026-49461 pypdf: Possible large memory usage for form XObjects during text extraction CWE-400--2026-06-22
CVE-2026-54531 pypdf: Possible infinite loop when processing outlines/bookmarks in writer CWE-835--2026-06-22
CVE-2026-54530 pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction CWE-835--2026-06-22
CVE-2026-48155 pypdf: Possible large memory usage for large offsets for layout mode text CWE-400--2026-05-28
CVE-2026-48156 pypdf: Possible long runtimes for zero-only width values in cross-reference streams CWE-834--2026-05-28
CVE-2026-48735 pypdf: Manipulated XMP metadata streams can exhaust RAM CWE-770--2026-05-28
CVE-2026-41314 pypdf: Manipulated FlateDecode image dimensions can exhaust RAM CWE-789 6.5AIMediumAI2026-04-22
CVE-2026-41313 pypdf: Possible long runtimes for wrong size values in incremental mode CWE-834 6.5AIMediumAI2026-04-22
CVE-2026-41312 pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM CWE-789 6.5AIMediumAI2026-04-22
CVE-2026-41168 pypdf has possible long runtimes for wrong size values in cross-reference and object streams CWE-834 4.3AIMediumAI2026-04-22
CVE-2026-40260 pypdf: Manipulated XMP metadata entity declarations can exhaust RAM CWE-776 6.5AIMediumAI2026-04-16
CVE-2026-33699 pypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_stream CWE-835 6.5 -2026-03-26
CVE-2026-33123 pypdf has inefficient decoding of array-based streams CWE-400 6.5 -2026-03-20
CVE-2026-31826 pypdf: manipulated stream length values can exhaust RAM CWE-770 4.3 -2026-03-10
CVE-2026-28804 pypdf: Inefficient decoding of ASCIIHexDecode streams CWE-407 6.5 -2026-03-06
CVE-2026-28351 Manipulated RunLengthDecode streams can exhaust RAM CWE-400 4.3 -2026-02-27
CVE-2026-27888 pypdf: Manipulated FlateDecode XFA streams can exhaust RAM CWE-400 6.5AIMediumAI2026-02-26
CVE-2026-27628 pypdf has a possible infinite loop when loading circular /Prev entries in cross-reference streams CWE-835 6.5 -2026-02-25
CVE-2026-27026 pypdf possibly has long runtimes for malformed FlateDecode streams CWE-770 6.5AIMediumAI2026-02-20
CVE-2026-27025 pypdf has possible long runtimes/large memory usage for large /ToUnicode streams CWE-834 6.5AIMediumAI2026-02-20
CVE-2026-27024 pypdf has a possible infinite loop when processing TreeObject CWE-835 6.5AIMediumAI2026-02-20

All 41 known CVE vulnerabilities affecting pypdf with full Chinese analysis, references, and POCs where available.