CVE-2026-49460
- EPSS 0.12%
- Veröffentlicht 22.06.2026 20:28:16
- Zuletzt bearbeitet 25.06.2026 16:51:17
pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /FlateDecode filter with a PNG predictor. ...
CVE-2026-49461
- EPSS 0.12%
- Veröffentlicht 22.06.2026 20:27:16
- Zuletzt bearbeitet 25.06.2026 16:48:15
pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires extracting the text of a page which contains a form XObject with self-r...
CVE-2026-54531
- EPSS 0.12%
- Veröffentlicht 22.06.2026 20:26:19
- Zuletzt bearbeitet 25.06.2026 16:46:14
pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with outlines into a writer. This vulnerability is fixed i...
CVE-2026-54530
- EPSS 0.12%
- Veröffentlicht 22.06.2026 20:25:29
- Zuletzt bearbeitet 25.06.2026 16:47:28
pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires extracting the text in layout mode. This vulnerability is fixed in 6.13.0...
CVE-2026-48155
- EPSS 0.13%
- Veröffentlicht 28.05.2026 14:51:49
- Zuletzt bearbeitet 29.05.2026 19:38:41
pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires extracting text in layout mode with large character offsets. This vulne...
CVE-2026-48156
- EPSS 0.12%
- Veröffentlicht 28.05.2026 14:50:41
- Zuletzt bearbeitet 29.05.2026 19:38:49
pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires cross-reference streams with /W [0 0 0] values and large /Size values. This ...
CVE-2026-48735
- EPSS 0.13%
- Veröffentlicht 28.05.2026 14:49:11
- Zuletzt bearbeitet 29.05.2026 19:38:59
pypdf is a free and open-source pure-python PDF library. Prior to 6.12.1, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing large XMP metadata, possibly with lots of unnecessary elements....
CVE-2026-41314
- EPSS 0.23%
- Veröffentlicht 22.04.2026 21:08:14
- Zuletzt bearbeitet 27.04.2026 19:29:40
pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to the RAM being exhausted. This requires accessing an image using `/FlateDecode` with large...
CVE-2026-41313
- EPSS 0.21%
- Veröffentlicht 22.04.2026 21:04:59
- Zuletzt bearbeitet 27.04.2026 19:30:37
pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to long runtimes. This requires loading a PDF with a large trailer `/Size` value in incremen...
CVE-2026-41312
- EPSS 0.23%
- Veröffentlicht 22.04.2026 21:02:53
- Zuletzt bearbeitet 27.04.2026 19:31:03
pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to the RAM being exhausted. This requires accessing a stream compressed using `/FlateDecode`...