Pypdf
This hub aggregates every CVE we track for Pypdf, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
39
CVEs tracked
0
Critical
10
High
0
In CISA KEV
Severity distribution
MEDIUM27HIGH10LOW2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
1
0
2
1
0
3
6
4
5
3
6
4
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Pypdf.
- CVE-2026-59936pypdf: Possible infinite loop for not terminated inline images7.5
- CVE-2026-59935pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)7.5
- CVE-2026-59937pypdf: Possible long runtimes for repeated malformed cross-reference entries7.5
- CVE-2026-59938pypdf: Possible large memory usage for wrong image dimensions5.3
- CVE-2026-57204pypdf: Missing stream length values ignore defined limits6.5
- CVE-2026-54651pypdf: Possible infinite loop when processing threads/articles in writer5.5
- CVE-2026-49460pypdf: Inefficient decoding of FlateDecode PNG predictor streams3.3
- CVE-2026-49461pypdf: Possible large memory usage for form XObjects during text extraction5.5
- CVE-2026-54531pypdf: Possible infinite loop when processing outlines/bookmarks in writer5.5
- CVE-2026-54530pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction5.5
- CVE-2026-48155pypdf: Possible large memory usage for large offsets for layout mode text5.5
- CVE-2026-48156pypdf: Possible long runtimes for zero-only width values in cross-reference streams3.3
- CVE-2026-48735pypdf: Manipulated XMP metadata streams can exhaust RAM5.5
- CVE-2026-41314pypdf: Manipulated FlateDecode image dimensions can exhaust RAM6.5
- CVE-2026-41313pypdf: Possible long runtimes for wrong size values in incremental mode6.5
Product normalization is registry-driven with AI assist and human review. How it works