Search CVE reports


Toggle filters

1 – 10 of 34 results


CVE-2026-84311

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_page.py PageObject._extract_text and PageObject.extract_xform_text to traverse a directed acyclic graph of...

2 affected packages

pypdf, pypdf2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pypdf Needs evaluation Needs evaluation Not in release — —
pypdf2 Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-84310

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consume long runtimes and large amounts of memory when retrieving document...

2 affected packages

pypdf, pypdf2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pypdf Needs evaluation Needs evaluation Not in release — —
pypdf2 Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-82398

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtimes when the pypdf/_utils.py function read_until_whitespace reads a stream containing a long run of bytes...

2 affected packages

pypdf, pypdf2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pypdf Needs evaluation Needs evaluation Not in release — —
pypdf2 Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-59936

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.14.1, an attacker can craft a PDF with a page content stream containing a not terminated inline image, causing an infinite loop during inline image end marker...

2 affected packages

pypdf, pypdf2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pypdf Needs evaluation Needs evaluation Not in release — —
pypdf2 Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-59935

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.14.2, an attacker can craft a PDF with a page content stream containing a not terminated inline image that uses the ASCII85 or ASCIIHex filters, causing an...

2 affected packages

pypdf, pypdf2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pypdf Needs evaluation Needs evaluation Not in release — —
pypdf2 Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-59938

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with declared image size values that are much too large compared to the actual data, causing large memory usage in pypdf image...

2 affected packages

pypdf, pypdf2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pypdf Needs evaluation Needs evaluation Not in release — —
pypdf2 Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-59937

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with repeated malformed cross-reference streams that cause pypdf to spend long runtimes recovering broken cross-reference table...

2 affected packages

pypdf, pypdf2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pypdf Needs evaluation Needs evaluation Not in release — —
pypdf2 Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-54651

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.13.1, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with threads/articles into a writer....

3 affected packages

pypdf, pypdf2, python-pypdf

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pypdf Needs evaluation Needs evaluation Not in release — —
pypdf2 Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
python-pypdf Not in release Not in release Not in release — —
Show less packages

CVE-2026-54531

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with outlines into a writer. This...

3 affected packages

pypdf, pypdf2, python-pypdf

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pypdf Needs evaluation Needs evaluation Not in release — —
pypdf2 Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
python-pypdf Not in release Not in release Not in release — —
Show less packages

CVE-2026-54530

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires extracting the text in layout mode....

3 affected packages

pypdf, pypdf2, python-pypdf

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pypdf Needs evaluation Needs evaluation Not in release — —
pypdf2 Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
python-pypdf Not in release Not in release Not in release — —
Show less packages