Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

pypdf — Vulnerabilities & Security Advisories 53

All 53 CVE vulnerabilities found in pypdf, with AI-generated Chinese analysis, references, and POCs.

This vulnerability aggregation page collects security advisories and weakness records for the pypdf software product. The database compiles known flaws in pypdf across a multi-year timeframe, capturing issues related to improper input validation, memory corruption, and deserialization risks. Readers can use this index to track pypdf’s historical vulnerability patterns, assess risk exposure, and review how weaknesses have evolved over time.

Vendor: py-pdf

CVE ID Title CVSS Severity Published
CVE-2026-103000 pypdf: Possible large memory usage when retrieving alphabetical page labels CWE-400 8.7 High 2026-09-30
CVE-2026-102999 pypdf: Possible long runtimes with large amount of embedded files CWE-400 8.7 High 2026-09-30
CVE-2026-102998 pypdf: Possible long runtimes when generating appearance streams CWE-400 8.7 High 2026-09-30
CVE-2026-102997 pypdf: Possible long runtimes for partially malformed FlateDecode streams (Follow-up) CWE-400 8.7 High 2026-09-30
CVE-2026-102996 pypdf: Possible large memory usage when parsing font data CWE-400 8.7 High 2026-09-30
CVE-2026-102995 pypdf: Possible large memory usage for large /ToUnicode streams (Follow-up 2) CWE-400 8.7 High 2026-09-30
CVE-2026-102994 pypdf: Possible long runtimes/large memory usage when parsing indirect objects CWE-400 8.7 High 2026-09-30
CVE-2026-102993 pypdf: Possible large memory usage when retrieving Roman page labels CWE-400 8.7 High 2026-09-30
CVE-2026-84311 pypdf: Possible long runtimes/large memory usage when extracting XForm objects CWE-834 4.8 Medium 2026-09-01
CVE-2026-84310 pypdf: Possible long runtimes/large memory usage when retrieving outlines CWE-405 4.8 Medium 2026-09-01
CVE-2026-84309 pypdf: Possible infinite loop for TreeObject.insert_child CWE-835 6.9 Medium 2026-09-01
CVE-2026-82398 pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace CWE-407 6.9 Medium 2026-08-31
CVE-2026-71870 pypdf: Possible large memory usage for large /ToUnicode streams CWE-400 4.8 Medium 2026-08-07
CVE-2026-71852 pypdf: Possible long runtimes/large memory usage for large CID font width ranges CWE-834 4.8 Medium 2026-08-07
CVE-2026-59936 pypdf: Possible infinite loop for not terminated inline images CWE-400 - - 2026-07-08
CVE-2026-59935 pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter) CWE-835 - - 2026-07-08
CVE-2026-59937 pypdf: Possible long runtimes for repeated malformed cross-reference entries CWE-400 - - 2026-07-08
CVE-2026-59938 pypdf: Possible large memory usage for wrong image dimensions CWE-789 - - 2026-07-08
CVE-2026-57204 pypdf: Missing stream length values ignore defined limits CWE-400 - - 2026-06-30
CVE-2026-54651 pypdf: Possible infinite loop when processing threads/articles in writer CWE-835 - - 2026-06-22
CVE-2026-49460 pypdf: Inefficient decoding of FlateDecode PNG predictor streams CWE-407 - - 2026-06-22
CVE-2026-49461 pypdf: Possible large memory usage for form XObjects during text extraction CWE-400 - - 2026-06-22
CVE-2026-54531 pypdf: Possible infinite loop when processing outlines/bookmarks in writer CWE-835 - - 2026-06-22
CVE-2026-54530 pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction CWE-835 - - 2026-06-22
CVE-2026-48155 pypdf: Possible large memory usage for large offsets for layout mode text CWE-400 - - 2026-05-28
CVE-2026-48156 pypdf: Possible long runtimes for zero-only width values in cross-reference streams CWE-834 - - 2026-05-28
CVE-2026-48735 pypdf: Manipulated XMP metadata streams can exhaust RAM CWE-770 - - 2026-05-28
CVE-2026-41314 pypdf: Manipulated FlateDecode image dimensions can exhaust RAM CWE-789 6.5AI Medium AI 2026-04-22
CVE-2026-41313 pypdf: Possible long runtimes for wrong size values in incremental mode CWE-834 6.5AI Medium AI 2026-04-22
CVE-2026-41312 pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM CWE-789 6.5AI Medium AI 2026-04-22

All 53 known CVE vulnerabilities affecting pypdf with full Chinese analysis, references, and POCs where available.