pypdf 是一个免费且开源的纯 Python PDF 库。在 6.18.1 版本之前,一个经过恶意构造的 PDF 文件可以提供一个 TrueType 或 Type1 简单字体,其 数组异常庞大。这会导致 中的 方法处理超出简单字体所支持的 256 个字符代码范围之外的条目,从而在执行文本提取等操作时消耗过量内存。该问题已在 6.18.1 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102998 | 8.7 HIGH | pypdf: Possible long runtimes when generating appearance streams |
| CVE-2026-102995 | 8.7 HIGH | pypdf: Possible large memory usage for large /ToUnicode streams (Follow-up 2) |
| CVE-2026-102997 | 8.7 HIGH | pypdf: Possible long runtimes for partially malformed FlateDecode streams (Follow-up) |
| CVE-2026-102993 | 8.7 HIGH | pypdf: Possible large memory usage when retrieving Roman page labels |
| CVE-2026-102994 | 8.7 HIGH | pypdf: Possible long runtimes/large memory usage when parsing indirect objects |
| CVE-2026-102999 | 8.7 HIGH | pypdf: Possible long runtimes with large amount of embedded files |
| CVE-2026-103000 | 8.7 HIGH | pypdf: Possible large memory usage when retrieving alphabetical page labels |
No comments yet