Vulnerabilities
38 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-59935 | pypdf is a free and open-source pure-python PDF library. pypdf is a free and open-source pure-python PDF library. Prior to 6.14.2, an attacker can craft a PDF with a page content stream containing a not terminated inline image that uses the ASCII85 or ASCIIHex filters, causing an infinite loop during parsing such as when extracting page text. This issue is fixed in version 6.14.2. NVD description · AI analysis pending | 8.7 group max | <1% |
| — | ||
| CVE-2026-57204 | pypdf is a free and open-source pure-python PDF library. pypdf is a free and open-source pure-python PDF library. Prior to 6.13.3, a maliciously crafted PDF can cause DoS. An attacker who uses this vulnerability can craft a PDF which leads to large memory usage, as MAX_DECLARED_STREAM_LENGTH is sometimes ignored. This requires parsing a content stream without a /Length value. This issue has been fixed in version 6.13.3. NVD description · AI analysis pending | 6.9 | <1% |
| — | ||
| CVE-2026-54531 | pypdf is a free and open-source pure-python PDF library. pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with outlines into a writer. This vulnerability is fixed in 6.13.0. NVD description · AI analysis pending | 6.9 group max | <1% |
| — | ||
| CVE-2026-48735 | pypdf is a free and open-source pure-python PDF library. pypdf is a free and open-source pure-python PDF library. Prior to 6.12.1, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing large XMP metadata, possibly with lots of unnecessary elements. This vulnerability is fixed in 6.12.1. NVD description · AI analysis pending | 6.9 group max | <1% |
| — | ||
| CVE-2026-41168 | pypdf is a free and open-source pure-python PDF library. pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.1 can craft a PDF which leads to long runtimes. This requires cross-reference streams with wrong large `/Size` values or object streams with wrong large `/N` values. This has been fixed in pypdf 6.10.1. As a workaround, one may apply the changes from the patch manually. NVD description · AI analysis pending | 6.9 group max | <1% |
| — | ||
| CVE-2026-40260 | pypdf is a free and open-source pure-python PDF library. pypdf is a free and open-source pure-python PDF library. In versions prior to 6.10.0, manipulated XMP metadata entity declarations can exhaust RAM. An attacker who exploits this vulnerability can craft a PDF which leads to large memory usage. This requires parsing the XMP metadata. This issue has been fixed in version 6.10.0. NVD description · AI analysis pending | 6.9 | <1% |
| — | ||
| CVE-2026-33699 | pypdf is a free and open-source pure-python PDF library. pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.2 have a vulnerability in which an attacker can craft a PDF which leads to an infinite loop. This requires reading a file in non-strict mode. This has been fixed in pypdf 6.9.2. If users cannot upgrade yet, consider applying the changes from the patch manually. NVD description · AI analysis pending | 4.6 | <1% |
| — | ||
| CVE-2026-33123 | pypdf is a free and open-source pure-python PDF library. pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.1 allow an attacker to craft a malicious PDF which leads to long runtimes and/or large memory usage. Exploitation requires accessing an array-based stream with many entries. This issue has been fixed in version 6.9.1. NVD description · AI analysis pending | 5.1 | <1% |
| — | ||
| CVE-2026-31826 | pypdf is a free and open-source pure-python PDF library. pypdf is a free and open-source pure-python PDF library. Prior to 6.8.0, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing a content stream with a rather large /Length value, regardless of the actual data length inside the stream. This vulnerability is fixed in 6.8.0. NVD description · AI analysis pending | 6.8 | <1% |
| — | ||
| CVE-2026-28804 | pypdf is a free and open-source pure-python PDF library. pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /ASCIIHexDecode filter. This issue has been patched in version 6.7.5. NVD description · AI analysis pending | 6.9 | <1% |
| — | ||
| CVE-2026-28351 | pypdf is a free and open-source pure-python PDF library. pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.4, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing the content stream using the RunLengthDecode filter. This has been fixed in pypdf 6.7.4. As a workaround, consider applying the changes from PR #3664. NVD description · AI analysis pending | 6.9 | <1% |
| — | ||
| CVE-2026-27888 | pypdf is a free and open-source pure-python PDF library. pypdf is a free and open-source pure-python PDF library. Prior to 6.7.3, an attacker who uses this vulnerability can craft a PDF which leads to the RAM being exhausted. This requires accessing the `xfa` property of a reader or writer and the corresponding stream being compressed using `/FlateDecode`. This has been fixed in pypdf 6.7.3. As a workaround, apply the patch manually. NVD description · AI analysis pending | 6.6 | <1% |
| — | ||
| CVE-2026-27628 | pypdf is a free and open-source pure-python PDF library. pypdf is a free and open-source pure-python PDF library. Prior to 6.7.2, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires reading the file. This has been fixed in pypdf 6.7.2. As a workaround, one may apply the patch manually. NVD description · AI analysis pending | 1.2 | <1% |
| — | ||
| CVE-2026-27026 | pypdf is a free and open-source pure-python PDF library. pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires a malformed /FlateDecode stream, where the byte-by-byte decompression is used. This vulnerability is fixed in 6.7.1. NVD description · AI analysis pending | 6.9 | <1% |
| — | ||
| CVE-2026-24688 | pypdf is a free and open-source pure-python PDF library. pypdf is a free and open-source pure-python PDF library. An attacker who uses an infinite loop vulnerability that is present in versions prior to 6.6.2 can craft a PDF which leads to an infinite loop. This requires accessing the outlines/bookmarks. This has been fixed in pypdf 6.6.2. If projects cannot upgrade yet, consider applying the changes from PR #3610 manually. NVD description · AI analysis pending | 5.1 | <1% |
| — | ||
| CVE-2026-22691 +1 in the same advisory: …22690 | pypdf is a free and open-source pure-python PDF library. pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for malformed startxref. An attacker who uses this vulnerability can craft a PDF which leads to possibly long runtimes for invalid startxref entries. When rebuilding the cross-reference table, PDF files with lots of whitespace characters become problematic. Only the non-strict reading mode is affected. Only the non-strict reading mode is affected. This issue has been patched in version 6.6.0. NVD description · AI analysis pending | 2.7 | <1% |
| — | ||
| CVE-2025-62708 +1 in the same advisory: …62707 | pypdf is a free and open-source pure-python PDF library. pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing the content stream of a page using the LZWDecode filter. This has been fixed in pypdf version 6.1.3. NVD description · AI analysis pending | 6.6 | <1% |
| — | ||
| CVE-2025-55197 | pypdf is a free and open-source pure-python PDF library. pypdf is a free and open-source pure-python PDF library. Prior to version 6.0.0, an attacker can craft a PDF which leads to the RAM being exhausted. This requires just reading the file if a series of FlateDecode filters is used on a malicious cross-reference stream. Other content streams are affected on explicit access. This issue has been fixed in 6.0.0. If an update is not possible, a workaround involves including the fixed code from pypdf.filters.decompress into the existing filters file. NVD description · AI analysis pending | 6.6 | <1% |
| — | ||
| CVE-2023-46250 | pypdf is a free and open-source pure-python PDF library. pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions 3.7.0 through 3.16.4 can craft a PDF which leads to an infinite loop. This infinite loop blocks the current process and can utilize a single core of the CPU by 100%. It does not affect memory usage. That is, for example, the case when the pypdf-user manipulates an incoming malicious PDF e.g. by merging it with another PDF or by adding annotations. The issue was fixed in version 3.17.0. As a workaround, apply the patch manually by modifying `pypdf/generic/_data_structures.py`. NVD description · AI analysis pending | 5.5 | <1% |
| — | ||
| CVE-2023-36810 +1 in the same advisory: …36807 | pypdf is a pure-python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files. pypdf is a pure-python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files. An attacker who uses this vulnerability can craft a PDF which leads to unexpected long runtime. This quadratic runtime blocks the current process and can utilize a single core of the CPU by 100%. It does not affect memory usage. This issue has been addressed in PR 808 and versions from 1.27.9 include this fix. Users are advised to upgrade. There are no known workarounds for this vulnerability. NVD description · AI analysis pending | 6.5 | <1% | PoC ×2 |
| — | |
| CVE-2023-36464 | pypdf is an open source, pure-python PDF library. pypdf is an open source, pure-python PDF library. In affected versions an attacker may craft a PDF which leads to an infinite loop if `__parse_content_stream` is executed. That is, for example, the case if the user extracted text from such a PDF. This issue was introduced in pull request #969 and resolved in pull request #1828. Users are advised to upgrade. Users unable to upgrade may modify the line `while peek not in (b"\r", b"\n")` in `pypdf/generic/_data_structures.py` to `while peek not in (b"\r", b"\n", b"")`. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — |