pypdf 是一个免费且开源的纯 Python PDF 库。在 6.19.0 版本之前,一个经过精心构造的 PDF 文件(包含表单字段值)可能导致 pypdf/generic/_appearance_stream.py 中的外观流生成逻辑在应用启用“扁平化”(flattening)选项更新字段时,在循环中重复执行不变的选择数据计算工作,从而导致运行时间过长并造成应用不可用。该问题已在 6.19.0 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102995 | 8.7 HIGH | pypdf: Possible large memory usage for large /ToUnicode streams (Follow-up 2) |
| CVE-2026-102997 | 8.7 HIGH | pypdf: Possible long runtimes for partially malformed FlateDecode streams (Follow-up) |
| CVE-2026-102993 | 8.7 HIGH | pypdf: Possible large memory usage when retrieving Roman page labels |
| CVE-2026-102994 | 8.7 HIGH | pypdf: Possible long runtimes/large memory usage when parsing indirect objects |
| CVE-2026-102996 | 8.7 HIGH | pypdf: Possible large memory usage when parsing font data |
| CVE-2026-102999 | 8.7 HIGH | pypdf: Possible long runtimes with large amount of embedded files |
| CVE-2026-103000 | 8.7 HIGH | pypdf: Possible large memory usage when retrieving alphabetical page labels |
No comments yet