Search CVE reports


Toggle filters

1 – 10 of 12 results


CVE-2026-27628

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.2, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires reading the file. This has been fixed in pypdf 6.7.2....

2 affected packages

pypdf, pypdf2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pypdf Needs evaluation Not in release
pypdf2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-27026

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires a malformed /FlateDecode stream, where the byte-by-byte...

2 affected packages

pypdf, pypdf2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pypdf Needs evaluation Not in release
pypdf2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-27025

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes and large memory consumption. This requires parsing the /ToUnicode entry...

2 affected packages

pypdf, pypdf2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pypdf Needs evaluation Not in release
pypdf2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-27024

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires accessing the children of a TreeObject, for example as...

2 affected packages

pypdf, pypdf2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pypdf Needs evaluation Not in release
pypdf2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-24688

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. An attacker who uses an infinite loop vulnerability that is present in versions prior to 6.6.2 can craft a PDF which leads to an infinite loop. This requires accessing the...

2 affected packages

pypdf, pypdf2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pypdf Needs evaluation Not in release
pypdf2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-22691

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for malformed startxref. An attacker who uses this vulnerability can craft a PDF which leads to possibly long...

2 affected packages

pypdf, pypdf2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pypdf Needs evaluation Not in release
pypdf2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-22690

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for missing /Root object with large /Size values. An attacker who uses this vulnerability can craft a PDF...

2 affected packages

pypdf, pypdf2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pypdf Needs evaluation Not in release
pypdf2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-55197

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to version 6.0.0, an attacker can craft a PDF which leads to the RAM being exhausted. This requires just reading the file if a series of FlateDecode filters is used on...

2 affected packages

pypdf, pypdf2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pypdf Needs evaluation Not in release
pypdf2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-46250

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions 3.7.0 through 3.16.4 can craft a PDF which leads to an infinite loop. This infinite loop blocks the current process...

2 affected packages

pypdf, pypdf2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pypdf Needs evaluation Not in release Not in release Ignored
pypdf2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-36810

Medium priority

Some fixes available 4 of 5

pypdf is a pure-python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files. An attacker who uses this vulnerability can craft a PDF which leads to unexpected long runtime. This quadratic...

1 affected package

pypdf2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pypdf2 Fixed Fixed Fixed
Show less packages