CVE-2026-84309
- EPSS 0.13%
- Veröffentlicht 01.09.2026 19:58:46
- Zuletzt bearbeitet 05.10.2026 17:42:16
pypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cyclic tree structure causes pypdf/generic/_data_structures.py TreeObject.insert_child to follow /Next links indefinitely when a writing code ...
CVE-2026-82398
- EPSS 0.3%
- Veröffentlicht 31.08.2026 21:41:10
- Zuletzt bearbeitet 05.10.2026 17:41:29
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtimes when the pypdf/_utils.py function read_until_whitespace reads a stream containing a long run of bytes without whitespace. ...
CVE-2026-71870
- EPSS 0.13%
- Veröffentlicht 07.08.2026 19:28:26
- Zuletzt bearbeitet 05.10.2026 17:41:13
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumption when pypdf/_cmap.py function parse_bfrange parses unusually large source-code or destination-string tokens in a font /ToUnicode...
CVE-2026-71852
- EPSS 0.13%
- Veröffentlicht 07.08.2026 19:18:54
- Zuletzt bearbeitet 05.10.2026 17:32:03
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause long runtimes and large memory consumption when pypdf/_font.py function Font._collect_cid_character_widths expands unusually large CID font /W width ran...
CVE-2026-59936
- EPSS 0.34%
- Veröffentlicht 08.07.2026 19:34:22
- Zuletzt bearbeitet 09.07.2026 20:41:41
pypdf is a free and open-source pure-python PDF library. Prior to 6.14.1, an attacker can craft a PDF with a page content stream containing a not terminated inline image, causing an infinite loop during inline image end marker detection such as when ...
CVE-2026-59935
- EPSS 0.37%
- Veröffentlicht 08.07.2026 19:34:15
- Zuletzt bearbeitet 09.07.2026 20:42:14
pypdf is a free and open-source pure-python PDF library. Prior to 6.14.2, an attacker can craft a PDF with a page content stream containing a not terminated inline image that uses the ASCII85 or ASCIIHex filters, causing an infinite loop during parsi...
CVE-2026-59937
- EPSS 0.34%
- Veröffentlicht 08.07.2026 17:25:34
- Zuletzt bearbeitet 09.07.2026 20:39:31
pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with repeated malformed cross-reference streams that cause pypdf to spend long runtimes recovering broken cross-reference table entries. This issue ...
CVE-2026-59938
- EPSS 0.33%
- Veröffentlicht 08.07.2026 17:24:29
- Zuletzt bearbeitet 09.07.2026 20:41:11
pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with declared image size values that are much too large compared to the actual data, causing large memory usage in pypdf image parsing. This issue i...
CVE-2026-57204
- EPSS 0.21%
- Veröffentlicht 30.06.2026 21:59:46
- Zuletzt bearbeitet 06.07.2026 16:21:07
pypdf is a free and open-source pure-python PDF library. Prior to 6.13.3, a maliciously crafted PDF can cause DoS. An attacker who uses this vulnerability can craft a PDF which leads to large memory usage, as MAX_DECLARED_STREAM_LENGTH is sometimes i...
CVE-2026-54651
- EPSS 0.11%
- Veröffentlicht 22.06.2026 20:28:28
- Zuletzt bearbeitet 24.06.2026 16:41:34
pypdf is a free and open-source pure-python PDF library. Prior to 6.13.1, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with threads/articles into a writer. This vulnerability is...