pypdf vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-71870Mediumpypdf: pypdf: Possible large memory usage for large /ToUnicode streamsCVE-2026-71852Mediumpypdf: pypdf: Possible long runtimes/large memory usage for large CID font width rangesCVE-2026-59935Highpypdf: pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)CVE-2026-59936Highpypdf: pypdf: Possible infinite loop for not terminated inline imagesCVE-2026-59937Mediumpypdf: pypdf: Possible long runtimes for repeated malformed cross-reference entries CVE-2026-59938Mediumpypdf: pypdf: Possible large memory usage for wrong image dimensionsCVE-2026-54651Mediumpypdf: pypdf: Possible infinite loop when processing threads/articles in writerGHSA-JM82-FX9C-MX94Mediumpypdf: pypdf: Missing stream length values ignore defined limitsCVE-2026-54531Mediumpypdf: pypdf: Possible infinite loop when processing outlines/bookmarks in writerCVE-2026-54530Mediumpypdf: pypdf: Possible infinite loop when retrieving fonts for layout-mode text extractionCVE-2026-49461Mediumpypdf: pypdf: Possible large memory usage for form XObjects during text extractionCVE-2026-49460Mediumpypdf: pypdf: Inefficient decoding of FlateDecode PNG predictor streamsCVE-2026-48735Mediumpypdf: pypdf: Manipulated XMP metadata streams can exhaust RAMCVE-2026-48156Mediumpypdf: pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference…CVE-2026-48155Mediumpypdf: pypdf: Possible large memory usage for large offsets for layout mode textCVE-2026-41314Mediumpypdf: pypdf: Manipulated FlateDecode image dimensions can exhaust RAMCVE-2026-41313Mediumpypdf: pypdf: Possible long runtimes for wrong size values in incremental modeCVE-2026-41312Mediumpypdf: pypdf: Manipulated FlateDecode predictor parameters can exhaust RAMCVE-2026-41168Mediumpypdf: pypdf has long runtimes for wrong size values in cross-reference and object streamsCVE-2026-40260Mediumpypdf: pypdf: Manipulated XMP metadata entity declarations can exhaust RAMCVE-2026-33699Mediumpypdf: pypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_streamCVE-2026-33123Mediumpypdf: pypdf has inefficient decoding of array-based streamsCVE-2026-31826Mediumpypdf: pypdf: manipulated stream length values can exhaust RAMCVE-2026-28804Mediumpypdf: pypdf vulnerable to inefficient decoding of ASCIIHexDecode streamsCVE-2026-28351Mediumpypdf: pypdf: Manipulated RunLengthDecode streams can exhaust RAM

Stop the waste.
Protect your environment with Kodem.