vciy

CVEs we hold for Py-pdf

Records whose assigning authority named Py-pdf as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-84311pypdf: Possible long runtimes/large memory usage when extracting XForm objectspy-pdf pypdf
CVE-2026-84310pypdf: Possible long runtimes/large memory usage when retrieving outlinespy-pdf pypdf
CVE-2026-84309pypdf: Possible infinite loop for TreeObject.insert_childpy-pdf pypdf
CVE-2026-82398pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespacepy-pdf pypdf
CVE-2026-71870pypdf: Possible large memory usage for large /ToUnicode streamspy-pdf pypdf
CVE-2026-71852pypdf: Possible long runtimes/large memory usage for large CID font width rangespy-pdf pypdf
CVE-2026-59938pypdf: Possible large memory usage for wrong image dimensionspy-pdf pypdf
CVE-2026-59937pypdf: Possible long runtimes for repeated malformed cross-reference entriespy-pdf pypdf
CVE-2026-59936pypdf: Possible infinite loop for not terminated inline imagespy-pdf pypdf
CVE-2026-59935pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)py-pdf pypdf
CVE-2026-57204pypdf: Missing stream length values ignore defined limitspy-pdf pypdf
CVE-2026-54651pypdf: Possible infinite loop when processing threads/articles in writerpy-pdf pypdf
CVE-2026-54531pypdf: Possible infinite loop when processing outlines/bookmarks in writerpy-pdf pypdf
CVE-2026-54530pypdf: Possible infinite loop when retrieving fonts for layout-mode text extractionpy-pdf pypdf
CVE-2026-49461pypdf: Possible large memory usage for form XObjects during text extractionpy-pdf pypdf
CVE-2026-49460pypdf: Inefficient decoding of FlateDecode PNG predictor streamspy-pdf pypdf
CVE-2026-48735pypdf: Manipulated XMP metadata streams can exhaust RAMpy-pdf pypdf
CVE-2026-48156pypdf: Possible long runtimes for zero-only width values in cross-reference streamspy-pdf pypdf
CVE-2026-48155pypdf: Possible large memory usage for large offsets for layout mode textpy-pdf pypdf
CVE-2026-41314pypdf: Manipulated FlateDecode image dimensions can exhaust RAMpy-pdf pypdf
CVE-2026-41313pypdf: Possible long runtimes for wrong size values in incremental modepy-pdf pypdf
CVE-2026-41312pypdf: Manipulated FlateDecode predictor parameters can exhaust RAMpy-pdf pypdf
CVE-2026-41168pypdf has possible long runtimes for wrong size values in cross-reference and object streamspy-pdf pypdf
CVE-2026-40260pypdf: Manipulated XMP metadata entity declarations can exhaust RAMpy-pdf pypdf
CVE-2026-33699pypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_streampy-pdf pypdf
CVE-2026-33123pypdf has inefficient decoding of array-based streamspy-pdf pypdf
CVE-2026-31826pypdf: manipulated stream length values can exhaust RAMpy-pdf pypdf
CVE-2026-28804pypdf: Inefficient decoding of ASCIIHexDecode streamspy-pdf pypdf
CVE-2026-28351Manipulated RunLengthDecode streams can exhaust RAMpy-pdf pypdf
CVE-2026-27888pypdf: Manipulated FlateDecode XFA streams can exhaust RAMpy-pdf pypdf
CVE-2026-27628pypdf has a possible infinite loop when loading circular /Prev entries in cross-reference streamspy-pdf pypdf
CVE-2026-27026pypdf possibly has long runtimes for malformed FlateDecode streamspy-pdf pypdf
CVE-2026-27025pypdf has possible long runtimes/large memory usage for large /ToUnicode streamspy-pdf pypdf
CVE-2026-27024pypdf has a possible infinite loop when processing TreeObjectpy-pdf pypdf
CVE-2026-24688pypdf has possible Infinite Loop when processing outlines/bookmarkspy-pdf pypdf
CVE-2026-22691pypdf has possible long runtimes for malformed startxrefpy-pdf pypdf
CVE-2026-22690pypdf has possible long runtimes for missing /Root object with large /Size valuespy-pdf pypdf
CVE-2025-66019pypdf manipulated LZWDecode streams can exhaust RAMpy-pdf pypdf
CVE-2025-62708pypdf manipulated LZWDecode streams can exhaust RAMpy-pdf pypdf
CVE-2025-62707pypdf affected by possible infinite loop when reading DCT inline images without EOF markerpy-pdf pypdf
CVE-2025-55197pypdf's Manipulated FlateDecode streams can exhaust RAMpy-pdf pypdf
CVE-2023-46250pypdf possible Infinite Loop when PdfWriter(clone_from) is used with a PDFpy-pdf pypdf
CVE-2023-36810Quadratic runtime with malformed PDF missing xref marker in pypdfpy-pdf pypdf
CVE-2023-36807Infinite Loop when reading malformed objects in pypdfpy-pdf pypdf
CVE-2023-36464Infinite Loop when a comment isn't followed by a character in pypdfpy-pdf pypdf
CVE-2022-24859Manipulated inline images can cause Infinite Loop in PyPDF2py-pdf PyPDF2

46 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.