Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

py-pdf — Vulnerabilities & Security Advisories 46

Browse all 46 CVE security advisories affecting py-pdf. AI-powered Chinese analysis, POCs, and references for each vulnerability.

py-pdf is a Python library designed for reading, writing, and manipulating PDF documents, serving developers who require programmatic access to PDF structures without heavy dependencies. Despite its utility, the project has accumulated twenty-seven Common Vulnerabilities and Exposures (CVEs), indicating significant historical security debt. The majority of these flaws involve remote code execution (RCE) and arbitrary file read vulnerabilities, often stemming from improper handling of malformed input or unsafe deserialization practices. While cross-site scripting (XSS) is less relevant in a backend library context, the potential for privilege escalation through crafted PDF files remains a critical concern. Notable incidents highlight the risks of processing untrusted documents, emphasizing the need for strict input validation. Users must exercise caution, ensuring they upgrade to patched versions to mitigate these persistent threats associated with legacy parsing logic.

Top products by py-pdf: pypdf PyPDF2
CVE ID Title CVSS Severity Published
CVE-2026-84311 pypdf: Possible long runtimes/large memory usage when extracting XForm objects — pypdf CWE-834 4.8 Medium 2026-09-01
CVE-2026-84310 pypdf: Possible long runtimes/large memory usage when retrieving outlines — pypdf CWE-405 4.8 Medium 2026-09-01
CVE-2026-84309 pypdf: Possible infinite loop for TreeObject.insert_child — pypdf CWE-835 6.9 Medium 2026-09-01
CVE-2026-82398 pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace — pypdf CWE-407 6.9 Medium 2026-08-31
CVE-2026-71870 pypdf: Possible large memory usage for large /ToUnicode streams — pypdf CWE-400 4.8 Medium 2026-08-07
CVE-2026-71852 pypdf: Possible long runtimes/large memory usage for large CID font width ranges — pypdf CWE-834 4.8 Medium 2026-08-07
CVE-2026-59936 pypdf: Possible infinite loop for not terminated inline images — pypdf CWE-400 - - 2026-07-08
CVE-2026-59935 pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter) — pypdf CWE-835 - - 2026-07-08
CVE-2026-59937 pypdf: Possible long runtimes for repeated malformed cross-reference entries — pypdf CWE-400 - - 2026-07-08
CVE-2026-59938 pypdf: Possible large memory usage for wrong image dimensions — pypdf CWE-789 - - 2026-07-08
CVE-2026-57204 pypdf: Missing stream length values ignore defined limits — pypdf CWE-400 - - 2026-06-30
CVE-2026-54651 pypdf: Possible infinite loop when processing threads/articles in writer — pypdf CWE-835 - - 2026-06-22
CVE-2026-49460 pypdf: Inefficient decoding of FlateDecode PNG predictor streams — pypdf CWE-407 - - 2026-06-22
CVE-2026-49461 pypdf: Possible large memory usage for form XObjects during text extraction — pypdf CWE-400 - - 2026-06-22
CVE-2026-54531 pypdf: Possible infinite loop when processing outlines/bookmarks in writer — pypdf CWE-835 - - 2026-06-22
CVE-2026-54530 pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction — pypdf CWE-835 - - 2026-06-22
CVE-2026-48155 pypdf: Possible large memory usage for large offsets for layout mode text — pypdf CWE-400 - - 2026-05-28
CVE-2026-48156 pypdf: Possible long runtimes for zero-only width values in cross-reference streams — pypdf CWE-834 - - 2026-05-28
CVE-2026-48735 pypdf: Manipulated XMP metadata streams can exhaust RAM — pypdf CWE-770 - - 2026-05-28
CVE-2026-41314 pypdf: Manipulated FlateDecode image dimensions can exhaust RAM — pypdf CWE-789 6.5AI Medium AI 2026-04-22
CVE-2026-41313 pypdf: Possible long runtimes for wrong size values in incremental mode — pypdf CWE-834 6.5AI Medium AI 2026-04-22
CVE-2026-41312 pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM — pypdf CWE-789 6.5AI Medium AI 2026-04-22
CVE-2026-41168 pypdf has possible long runtimes for wrong size values in cross-reference and object streams — pypdf CWE-834 4.3AI Medium AI 2026-04-22
CVE-2026-40260 pypdf: Manipulated XMP metadata entity declarations can exhaust RAM — pypdf CWE-776 6.5AI Medium AI 2026-04-16
CVE-2026-33699 pypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_stream — pypdf CWE-835 6.5 - 2026-03-26
CVE-2026-33123 pypdf has inefficient decoding of array-based streams — pypdf CWE-400 6.5 - 2026-03-20
CVE-2026-31826 pypdf: manipulated stream length values can exhaust RAM — pypdf CWE-770 4.3 - 2026-03-10
CVE-2026-28804 pypdf: Inefficient decoding of ASCIIHexDecode streams — pypdf CWE-407 6.5 - 2026-03-06
CVE-2026-28351 Manipulated RunLengthDecode streams can exhaust RAM — pypdf CWE-400 4.3 - 2026-02-27
CVE-2026-27888 pypdf: Manipulated FlateDecode XFA streams can exhaust RAM — pypdf CWE-400 6.5AI Medium AI 2026-02-26

This page lists every published CVE security advisory associated with py-pdf. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.