pypdf 是一个免费且开源的纯 Python PDF 库。在 6.19.0 版本之前,一个经过精心构造的 PDF 文件若包含大量嵌入文件,会导致 pypdf/_doc_common.py 中基于字典的附件 API 在每次内容查找时重新解析完整的附件列表,从而产生重复计算并导致长时间运行。当应用程序访问嵌入文件映射时,此问题尤为明显。该问题已在 6.19.0 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102998 | 8.7 HIGH | pypdf: Possible long runtimes when generating appearance streams |
| CVE-2026-102995 | 8.7 HIGH | pypdf: Possible large memory usage for large /ToUnicode streams (Follow-up 2) |
| CVE-2026-102997 | 8.7 HIGH | pypdf: Possible long runtimes for partially malformed FlateDecode streams (Follow-up) |
| CVE-2026-102993 | 8.7 HIGH | pypdf: Possible large memory usage when retrieving Roman page labels |
| CVE-2026-102994 | 8.7 HIGH | pypdf: Possible long runtimes/large memory usage when parsing indirect objects |
| CVE-2026-102996 | 8.7 HIGH | pypdf: Possible large memory usage when parsing font data |
| CVE-2026-103000 | 8.7 HIGH | pypdf: Possible large memory usage when retrieving alphabetical page labels |
No comments yet