pypdf
PyPI51 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting pypdfpage 1 of 2
- CVE-2023-36464MEDIUMCVSS 6.2EG 6.2fixed in 3.9.02023-06-27
vulnerable: 3.1.0 ... 3.8.1 (14 versions)
pypdf is an open source, pure-python PDF library. In affected versions an attacker may craft a PDF which leads to an infinite loop if `__parse_content_stream` is executed. That is, for example, the case if the user extracted text from such…
- CVE-2023-46250MEDIUMCVSS 5.5EG 5.5fixed in 3.17.02023-10-31
vulnerable: 3.10.0 ... 3.9.1 (25 versions)
pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions 3.7.0 through 3.16.4 can craft a PDF which leads to an infinite loop. This infinite loop blocks the current process and can u…
- CVE-2025-55197HIGHCVSS 7.5EG 7.5fixed in 6.0.02025-08-13
vulnerable: 1.0 ... 5.9.0 (74 versions)
pypdf is a free and open-source pure-python PDF library. Prior to version 6.0.0, an attacker can craft a PDF which leads to the RAM being exhausted. This requires just reading the file if a series of FlateDecode filters is used on a malici…
- CVE-2025-62707HIGHCVSS 7.5EG 7.5fixed in 6.1.32025-10-22
vulnerable: 1.0 ... 6.1.2 (78 versions)
pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires parsing the content stream of a page which has an inlin…
- CVE-2025-62708HIGHCVSS 7.5EG 7.5fixed in 6.1.32025-10-22
vulnerable: 1.0 ... 6.1.2 (78 versions)
pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing the content stream of a page using the LZWDec…
- CVE-2025-66019MEDIUMCVSS 6.6EG 6.6fixed in 6.4.02025-11-26
vulnerable: 1.0 ... 6.3.0 (81 versions)
pypdf is a free and open-source pure-python PDF library. Prior to version 6.4.0, an attacker who uses this vulnerability can craft a PDF which leads to a memory usage of up to 1 GB per stream. This requires parsing the content stream of a …
- CVE-2026-102993HIGHCVSS 7.5EG 7.5fixed in 6.17.02026-09-30
vulnerable: 1.0 ... 6.9.2 (116 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an application …
- CVE-2026-102994HIGHCVSS 7.5EG 7.5fixed in 6.18.02026-09-30
vulnerable: 1.0 ... 6.9.2 (117 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.18.0, a crafted PDF containing indirect-object identifiers or generation-number tokens that continue for a long time without whitespace can cause pypdf/_reader.py and pypd…
- CVE-2026-102995HIGHCVSS 7.5EG 7.5fixed in 6.18.12026-09-30
vulnerable: 1.0 ... 6.9.2 (118 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can place unusually large source-code or destination-string tokens in a font /ToUnicode mapping, causing pypdf/_cmap.py parse_bfchar to decode and reta…
- CVE-2026-102996HIGHCVSS 7.5EG 7.5fixed in 6.18.12026-09-30
vulnerable: 1.0 ... 6.9.2 (118 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can provide a TrueType or Type1 simple font with an unusually large /Widths array, causing pypdf/_font.py Font._collect_tt_t1_character_widths to proce…
- CVE-2026-102997HIGHCVSS 7.5EG 7.5fixed in 6.18.12026-09-30
vulnerable: 1.0 ... 6.9.2 (118 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF containing a partially malformed /FlateDecode stream with padded data can force pypdf/filters.py to use inefficient byte-by-byte decompression while th…
- CVE-2026-102998HIGHCVSS 7.5EG 7.5fixed in 6.19.02026-09-30
vulnerable: 1.0 ... 6.9.2 (119 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF with form field values can cause pypdf/generic/_appearance_stream.py appearance-stream generation to repeat invariant selection-data work inside a loop…
- CVE-2026-102999HIGHCVSS 7.5EG 7.5fixed in 6.19.02026-09-30
vulnerable: 1.0 ... 6.9.2 (119 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF containing many embedded files can cause the dictionary-based attachments API in pypdf/_doc_common.py to reparse the full attachment list for each cont…
- CVE-2026-103000HIGHCVSS 7.5EG 7.5fixed in 6.19.02026-09-30
vulnerable: 1.0 ... 6.9.2 (119 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF can provide unusually large alphabetical page-label values that cause pypdf/_page_labels.py to generate strings beyond a reasonable page-label length w…
- CVE-2026-22690MEDIUMCVSS 5.3EG 5.3fixed in 6.6.02026-01-10
vulnerable: 1.0 ... 6.5.0 (85 versions)
pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for missing /Root object with large /Size values. An attacker who uses this vulnerability can craft a PDF which leads to poss…
- CVE-2026-22691MEDIUMCVSS 5.3EG 5.3fixed in 6.6.02026-01-10
vulnerable: 1.0 ... 6.5.0 (85 versions)
pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for malformed startxref. An attacker who uses this vulnerability can craft a PDF which leads to possibly long runtimes for in…
- CVE-2026-24688MEDIUMCVSS 4.3EG 4.3fixed in 6.6.22026-01-27
vulnerable: 1.0 ... 6.6.1 (87 versions)
pypdf is a free and open-source pure-python PDF library. An attacker who uses an infinite loop vulnerability that is present in versions prior to 6.6.2 can craft a PDF which leads to an infinite loop. This requires accessing the outlines/b…
- CVE-2026-27024MEDIUMCVSS 5.5EG 5.5fixed in 6.7.12026-02-20
vulnerable: 1.0 ... 6.7.0 (89 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires accessing the children of a TreeObject, for example as part of …
- CVE-2026-27025MEDIUMCVSS 5.5EG 5.5fixed in 6.7.12026-02-20
vulnerable: 1.0 ... 6.7.0 (89 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes and large memory consumption. This requires parsing the /ToUnicode entry of a fon…
- CVE-2026-27026MEDIUMCVSS 5.5EG 5.5fixed in 6.7.12026-02-20
vulnerable: 1.0 ... 6.7.0 (89 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires a malformed /FlateDecode stream, where the byte-by-byte decompress…
- CVE-2026-27628HIGHCVSS 7.5EG 7.5fixed in 6.7.22026-02-25
vulnerable: 1.0 ... 6.7.1 (90 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.7.2, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires reading the file. This has been fixed in pypdf 6.7.2. As a work…
- CVE-2026-27888MEDIUMCVSS 6.6EG 6.6fixed in 6.7.32026-02-26
vulnerable: 1.0 ... 6.7.2 (91 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.7.3, an attacker who uses this vulnerability can craft a PDF which leads to the RAM being exhausted. This requires accessing the `xfa` property of a reader or writer and t…
- CVE-2026-28351MEDIUMCVSS 5.3EG 5.3fixed in 6.7.42026-02-27
vulnerable: 1.0 ... 6.7.3 (92 versions)
pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.4, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing the content stream using the RunLengthDecode …
- CVE-2026-28804MEDIUMCVSS 5.3EG 5.3fixed in 6.7.52026-03-06
vulnerable: 1.0 ... 6.7.4 (93 versions)
pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /ASCIIHexDecode filter. …
- CVE-2026-31826MEDIUMCVSS 5.5EG 5.5fixed in 6.8.02026-03-10
vulnerable: 1.0 ... 6.7.5 (94 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.8.0, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing a content stream with a rather large /Length value, r…
- CVE-2026-33123MEDIUMCVSS 6.5EG 6.5fixed in 6.9.12026-03-20
vulnerable: 1.0 ... 6.9.0 (96 versions)
pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.1 allow an attacker to craft a malicious PDF which leads to long runtimes and/or large memory usage. Exploitation requires accessing an array-based stream with …
- CVE-2026-33699HIGHCVSS 7.5EG 7.5fixed in 6.9.22026-03-26
vulnerable: 1.0 ... 6.9.1 (97 versions)
pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.2 have a vulnerability in which an attacker can craft a PDF which leads to an infinite loop. This requires reading a file in non-strict mode. This has been fixe…
- CVE-2026-40260MEDIUMCVSS 5.3EG 5.3fixed in 6.10.02026-04-17
vulnerable: 1.0 ... 6.9.2 (98 versions)
pypdf is a free and open-source pure-python PDF library. In versions prior to 6.10.0, manipulated XMP metadata entity declarations can exhaust RAM. An attacker who exploits this vulnerability can craft a PDF which leads to large memory usa…
- CVE-2026-41168MEDIUMCVSS 5.3EG 5.3fixed in 6.10.12026-04-22
vulnerable: 1.0 ... 6.9.2 (99 versions)
pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.1 can craft a PDF which leads to long runtimes. This requires cross-reference streams with wrong large `/Size` …
- CVE-2026-41312MEDIUMCVSS 6.5EG 6.5fixed in 6.10.22026-04-22
vulnerable: 1.0 ... 6.9.2 (100 versions)
pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to the RAM being exhausted. This requires accessing a stream compressed using `/F…
- CVE-2026-41313MEDIUMCVSS 6.5EG 6.5fixed in 6.10.22026-04-22
vulnerable: 1.0 ... 6.9.2 (100 versions)
pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to long runtimes. This requires loading a PDF with a large trailer `/Size` value …
- CVE-2026-41314MEDIUMCVSS 6.5EG 6.5fixed in 6.10.22026-04-22
vulnerable: 1.0 ... 6.9.2 (100 versions)
pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to the RAM being exhausted. This requires accessing an image using `/FlateDecode`…
- CVE-2026-48155MEDIUMCVSS 5.5EG 5.5fixed in 6.12.02026-05-28
vulnerable: 1.0 ... 6.9.2 (102 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires extracting text in layout mode with large character offsets.…
- CVE-2026-48156MEDIUMCVSS 5.1EG 5.1fixed in 6.12.02026-05-28
vulnerable: 1.0 ... 6.9.2 (102 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires cross-reference streams with /W [0 0 0] values and large /Size va…
- CVE-2026-48735MEDIUMCVSS 6.9EG 6.9fixed in 6.12.12026-05-28
vulnerable: 1.0 ... 6.9.2 (103 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.12.1, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing large XMP metadata, possibly with lots of unnecessar…
- CVE-2026-49460LOWCVSS 3.3EG 3.3fixed in 6.12.22026-06-16
vulnerable: 1.0 ... 6.9.2 (104 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /FlateDecode filter with a PNG …
- CVE-2026-49461MEDIUMCVSS 5.5EG 5.5fixed in 6.12.22026-06-16
vulnerable: 1.0 ... 6.9.2 (104 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires extracting the text of a page which contains a form XObject …
- CVE-2026-54530MEDIUMCVSS 5.5EG 5.5fixed in 6.13.02026-06-16
vulnerable: 1.0 ... 6.9.2 (105 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires extracting the text in layout mode. This vulnerability is fixe…
- CVE-2026-54531MEDIUMCVSS 5.5EG 5.5fixed in 6.13.02026-06-16
vulnerable: 1.0 ... 6.9.2 (105 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with outlines into a writer. This vulnerability…
- CVE-2026-54651MEDIUMCVSS 5.5EG 5.5fixed in 6.13.12026-06-22
vulnerable: 1.0 ... 6.9.2 (106 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.13.1, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with threads/articles into a writer. This vulne…
- CVE-2026-57204MEDIUMCVSS 6.5EG 6.5fixed in 6.13.32026-06-30
vulnerable: 1.0 ... 6.9.2 (108 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.13.3, a maliciously crafted PDF can cause DoS. An attacker who uses this vulnerability can craft a PDF which leads to large memory usage, as MAX_DECLARED_STREAM_LENGTH is …
- CVE-2026-59935HIGHCVSS 7.5EG 7.5fixed in 6.14.22026-07-08
vulnerable: 1.0 ... 6.9.2 (111 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.14.2, an attacker can craft a PDF with a page content stream containing a not terminated inline image that uses the ASCII85 or ASCIIHex filters, causing an infinite loop d…
- CVE-2026-59936HIGHCVSS 7.5EG 7.5fixed in 6.14.12026-07-08
vulnerable: 1.0 ... 6.9.2 (110 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.14.1, an attacker can craft a PDF with a page content stream containing a not terminated inline image, causing an infinite loop during inline image end marker detection su…
- CVE-2026-59937HIGHCVSS 7.5EG 7.5fixed in 6.14.02026-07-08
vulnerable: 1.0 ... 6.9.2 (109 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with repeated malformed cross-reference streams that cause pypdf to spend long runtimes recovering broken cross-reference table entries. …
- CVE-2026-59938MEDIUMCVSS 5.3EG 5.3fixed in 6.14.02026-07-08
vulnerable: 1.0 ... 6.9.2 (109 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with declared image size values that are much too large compared to the actual data, causing large memory usage in pypdf image parsing. T…
- CVE-2026-71852LOWCVSS 3.3EG 3.3fixed in 6.15.02026-08-07
vulnerable: 1.0 ... 6.9.2 (112 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause long runtimes and large memory consumption when pypdf/_font.py function Font._collect_cid_character_widths expands unusually large CID font /…
- CVE-2026-71870LOWCVSS 3.3EG 3.3fixed in 6.15.02026-08-07
vulnerable: 1.0 ... 6.9.2 (112 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumption when pypdf/_cmap.py function parse_bfrange parses unusually large source-code or destination-string tokens in a font…
- CVE-2026-82398MEDIUMCVSS 5.3EG 5.3fixed in 6.15.02026-08-31
vulnerable: 1.0 ... 6.9.2 (112 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtimes when the pypdf/_utils.py function read_until_whitespace reads a stream containing a long run of bytes without w…
- CVE-2026-84309MEDIUMCVSS 5.5EG 5.5fixed in 6.16.02026-09-01
vulnerable: 1.0 ... 6.9.2 (113 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cyclic tree structure causes pypdf/generic/_data_structures.py TreeObject.insert_child to follow /Next links indefinitely when a wr…
- CVE-2026-84310LOWCVSS 3.3EG 3.3fixed in 6.16.12026-09-01
vulnerable: 1.0 ... 6.9.2 (114 versions)
pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consume long runtimes and large amounts of memory when retrieving document outlines with…
Check whether pypdf is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for pypdf CVEs against the assets you own.
Book a Demo →