Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

py-pdf — Vulnerabilities & Security Advisories 54

Browse all 54 CVE security advisories affecting py-pdf. AI-powered Chinese analysis, POCs, and references for each vulnerability.

py-pdf is a Python library designed for reading, writing, and manipulating PDF documents, serving developers who require programmatic access to PDF structures without heavy dependencies. Despite its utility, the project has accumulated twenty-seven Common Vulnerabilities and Exposures (CVEs), indicating significant historical security debt. The majority of these flaws involve remote code execution (RCE) and arbitrary file read vulnerabilities, often stemming from improper handling of malformed input or unsafe deserialization practices. While cross-site scripting (XSS) is less relevant in a backend library context, the potential for privilege escalation through crafted PDF files remains a critical concern. Notable incidents highlight the risks of processing untrusted documents, emphasizing the need for strict input validation. Users must exercise caution, ensuring they upgrade to patched versions to mitigate these persistent threats associated with legacy parsing logic.

Found 53 results / 54 Clear Filters
Top products by py-pdf: pypdf PyPDF2
CVE ID Title CVSS Severity Published
CVE-2026-103000 pypdf: Possible large memory usage when retrieving alphabetical page labels — pypdf CWE-400 8.7 High 2026-09-30
CVE-2026-102999 pypdf: Possible long runtimes with large amount of embedded files — pypdf CWE-400 8.7 High 2026-09-30
CVE-2026-102998 pypdf: Possible long runtimes when generating appearance streams — pypdf CWE-400 8.7 High 2026-09-30
CVE-2026-102997 pypdf: Possible long runtimes for partially malformed FlateDecode streams (Follow-up) — pypdf CWE-400 8.7 High 2026-09-30
CVE-2026-102996 pypdf: Possible large memory usage when parsing font data — pypdf CWE-400 8.7 High 2026-09-30
CVE-2026-102995 pypdf: Possible large memory usage for large /ToUnicode streams (Follow-up 2) — pypdf CWE-400 8.7 High 2026-09-30
CVE-2026-102994 pypdf: Possible long runtimes/large memory usage when parsing indirect objects — pypdf CWE-400 8.7 High 2026-09-30
CVE-2026-102993 pypdf: Possible large memory usage when retrieving Roman page labels — pypdf CWE-400 8.7 High 2026-09-30
CVE-2026-84311 pypdf: Possible long runtimes/large memory usage when extracting XForm objects — pypdf CWE-834 4.8 Medium 2026-09-01
CVE-2026-84310 pypdf: Possible long runtimes/large memory usage when retrieving outlines — pypdf CWE-405 4.8 Medium 2026-09-01
CVE-2026-84309 pypdf: Possible infinite loop for TreeObject.insert_child — pypdf CWE-835 6.9 Medium 2026-09-01
CVE-2026-82398 pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace — pypdf CWE-407 6.9 Medium 2026-08-31
CVE-2026-71870 pypdf: Possible large memory usage for large /ToUnicode streams — pypdf CWE-400 4.8 Medium 2026-08-07
CVE-2026-71852 pypdf: Possible long runtimes/large memory usage for large CID font width ranges — pypdf CWE-834 4.8 Medium 2026-08-07
CVE-2026-59936 pypdf: Possible infinite loop for not terminated inline images — pypdf CWE-400 - - 2026-07-08
CVE-2026-59935 pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter) — pypdf CWE-835 - - 2026-07-08
CVE-2026-59937 pypdf: Possible long runtimes for repeated malformed cross-reference entries — pypdf CWE-400 - - 2026-07-08
CVE-2026-59938 pypdf: Possible large memory usage for wrong image dimensions — pypdf CWE-789 - - 2026-07-08
CVE-2026-57204 pypdf: Missing stream length values ignore defined limits — pypdf CWE-400 - - 2026-06-30
CVE-2026-54651 pypdf: Possible infinite loop when processing threads/articles in writer — pypdf CWE-835 - - 2026-06-22
CVE-2026-49460 pypdf: Inefficient decoding of FlateDecode PNG predictor streams — pypdf CWE-407 - - 2026-06-22
CVE-2026-49461 pypdf: Possible large memory usage for form XObjects during text extraction — pypdf CWE-400 - - 2026-06-22
CVE-2026-54531 pypdf: Possible infinite loop when processing outlines/bookmarks in writer — pypdf CWE-835 - - 2026-06-22
CVE-2026-54530 pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction — pypdf CWE-835 - - 2026-06-22
CVE-2026-48155 pypdf: Possible large memory usage for large offsets for layout mode text — pypdf CWE-400 - - 2026-05-28
CVE-2026-48156 pypdf: Possible long runtimes for zero-only width values in cross-reference streams — pypdf CWE-834 - - 2026-05-28
CVE-2026-48735 pypdf: Manipulated XMP metadata streams can exhaust RAM — pypdf CWE-770 - - 2026-05-28
CVE-2026-41314 pypdf: Manipulated FlateDecode image dimensions can exhaust RAM — pypdf CWE-789 6.5AI Medium AI 2026-04-22
CVE-2026-41313 pypdf: Possible long runtimes for wrong size values in incremental mode — pypdf CWE-834 6.5AI Medium AI 2026-04-22
CVE-2026-41312 pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM — pypdf CWE-789 6.5AI Medium AI 2026-04-22

This page lists every published CVE security advisory associated with py-pdf. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.