CVE-2026-27025
- EPSS 0.17%
- Veröffentlicht 20.02.2026 21:11:20
- Zuletzt bearbeitet 24.02.2026 15:16:48
pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes and large memory consumption. This requires parsing the /ToUnicode entry of a font with unus...
CVE-2026-27024
- EPSS 0.17%
- Veröffentlicht 20.02.2026 21:10:07
- Zuletzt bearbeitet 24.02.2026 15:19:23
pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires accessing the children of a TreeObject, for example as part of outlines. T...
CVE-2026-24688
- EPSS 0.39%
- Veröffentlicht 27.01.2026 19:44:06
- Zuletzt bearbeitet 25.02.2026 17:40:23
pypdf is a free and open-source pure-python PDF library. An attacker who uses an infinite loop vulnerability that is present in versions prior to 6.6.2 can craft a PDF which leads to an infinite loop. This requires accessing the outlines/bookmarks. T...
CVE-2026-22691
- EPSS 0.41%
- Veröffentlicht 10.01.2026 04:46:12
- Zuletzt bearbeitet 22.01.2026 15:01:05
pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for malformed startxref. An attacker who uses this vulnerability can craft a PDF which leads to possibly long runtimes for invalid start...
CVE-2026-22690
- EPSS 0.41%
- Veröffentlicht 10.01.2026 04:41:20
- Zuletzt bearbeitet 22.01.2026 15:35:23
pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for missing /Root object with large /Size values. An attacker who uses this vulnerability can craft a PDF which leads to possibly long r...
CVE-2025-62708
- EPSS 0.41%
- Veröffentlicht 22.10.2025 21:36:56
- Zuletzt bearbeitet 08.10.2026 11:10:00
pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing the content stream of a page using the LZWDecode filter....
CVE-2025-62707
- EPSS 0.41%
- Veröffentlicht 22.10.2025 21:36:32
- Zuletzt bearbeitet 08.10.2026 11:10:00
pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires parsing the content stream of a page which has an inline image usi...
CVE-2025-55197
- EPSS 0.44%
- Veröffentlicht 13.08.2025 23:15:27
- Zuletzt bearbeitet 15.08.2025 20:05:20
pypdf is a free and open-source pure-python PDF library. Prior to version 6.0.0, an attacker can craft a PDF which leads to the RAM being exhausted. This requires just reading the file if a series of FlateDecode filters is used on a malicious cross-r...
CVE-2023-46250
- EPSS 0.24%
- Veröffentlicht 31.10.2023 16:15:09
- Zuletzt bearbeitet 21.11.2024 08:28:10
pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions 3.7.0 through 3.16.4 can craft a PDF which leads to an infinite loop. This infinite loop blocks the current process and can utilize a si...
CVE-2023-36810
- EPSS 0.63%
- Veröffentlicht 30.06.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:10:38
pypdf is a pure-python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files. An attacker who uses this vulnerability can craft a PDF which leads to unexpected long runtime. This quadratic runtime blocks the cur...