CVEs we hold for Py-pdf
Records whose assigning authority named Py-pdf as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-84311pypdf: Possible long runtimes/large memory usage when extracting XForm objectspy-pdf pypdf CVE-2026-84310pypdf: Possible long runtimes/large memory usage when retrieving outlinespy-pdf pypdf CVE-2026-84309pypdf: Possible infinite loop for TreeObject.insert_childpy-pdf pypdf CVE-2026-82398pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespacepy-pdf pypdf CVE-2026-71870pypdf: Possible large memory usage for large /ToUnicode streamspy-pdf pypdf CVE-2026-71852pypdf: Possible long runtimes/large memory usage for large CID font width rangespy-pdf pypdf CVE-2026-59938pypdf: Possible large memory usage for wrong image dimensionspy-pdf pypdf CVE-2026-59937pypdf: Possible long runtimes for repeated malformed cross-reference entriespy-pdf pypdf CVE-2026-59936pypdf: Possible infinite loop for not terminated inline imagespy-pdf pypdf CVE-2026-59935pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)py-pdf pypdf CVE-2026-57204pypdf: Missing stream length values ignore defined limitspy-pdf pypdf CVE-2026-54651pypdf: Possible infinite loop when processing threads/articles in writerpy-pdf pypdf CVE-2026-54531pypdf: Possible infinite loop when processing outlines/bookmarks in writerpy-pdf pypdf CVE-2026-54530pypdf: Possible infinite loop when retrieving fonts for layout-mode text extractionpy-pdf pypdf CVE-2026-49461pypdf: Possible large memory usage for form XObjects during text extractionpy-pdf pypdf CVE-2026-49460pypdf: Inefficient decoding of FlateDecode PNG predictor streamspy-pdf pypdf CVE-2026-48735pypdf: Manipulated XMP metadata streams can exhaust RAMpy-pdf pypdf CVE-2026-48156pypdf: Possible long runtimes for zero-only width values in cross-reference streamspy-pdf pypdf CVE-2026-48155pypdf: Possible large memory usage for large offsets for layout mode textpy-pdf pypdf CVE-2026-41314pypdf: Manipulated FlateDecode image dimensions can exhaust RAMpy-pdf pypdf CVE-2026-41313pypdf: Possible long runtimes for wrong size values in incremental modepy-pdf pypdf CVE-2026-41312pypdf: Manipulated FlateDecode predictor parameters can exhaust RAMpy-pdf pypdf CVE-2026-41168pypdf has possible long runtimes for wrong size values in cross-reference and object streamspy-pdf pypdf CVE-2026-40260pypdf: Manipulated XMP metadata entity declarations can exhaust RAMpy-pdf pypdf CVE-2026-33699pypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_streampy-pdf pypdf CVE-2026-33123pypdf has inefficient decoding of array-based streamspy-pdf pypdf CVE-2026-31826pypdf: manipulated stream length values can exhaust RAMpy-pdf pypdf CVE-2026-28804pypdf: Inefficient decoding of ASCIIHexDecode streamspy-pdf pypdf CVE-2026-28351Manipulated RunLengthDecode streams can exhaust RAMpy-pdf pypdf CVE-2026-27888pypdf: Manipulated FlateDecode XFA streams can exhaust RAMpy-pdf pypdf CVE-2026-27628pypdf has a possible infinite loop when loading circular /Prev entries in cross-reference streamspy-pdf pypdf CVE-2026-27026pypdf possibly has long runtimes for malformed FlateDecode streamspy-pdf pypdf CVE-2026-27025pypdf has possible long runtimes/large memory usage for large /ToUnicode streamspy-pdf pypdf CVE-2026-27024pypdf has a possible infinite loop when processing TreeObjectpy-pdf pypdf CVE-2026-24688pypdf has possible Infinite Loop when processing outlines/bookmarkspy-pdf pypdf CVE-2026-22691pypdf has possible long runtimes for malformed startxrefpy-pdf pypdf CVE-2026-22690pypdf has possible long runtimes for missing /Root object with large /Size valuespy-pdf pypdf CVE-2025-66019pypdf manipulated LZWDecode streams can exhaust RAMpy-pdf pypdf CVE-2025-62708pypdf manipulated LZWDecode streams can exhaust RAMpy-pdf pypdf CVE-2025-62707pypdf affected by possible infinite loop when reading DCT inline images without EOF markerpy-pdf pypdf CVE-2025-55197pypdf's Manipulated FlateDecode streams can exhaust RAMpy-pdf pypdf CVE-2023-46250pypdf possible Infinite Loop when PdfWriter(clone_from) is used with a PDFpy-pdf pypdf CVE-2023-36810Quadratic runtime with malformed PDF missing xref marker in pypdfpy-pdf pypdf CVE-2023-36807Infinite Loop when reading malformed objects in pypdfpy-pdf pypdf CVE-2023-36464Infinite Loop when a comment isn't followed by a character in pypdfpy-pdf pypdf CVE-2022-24859Manipulated inline images can cause Infinite Loop in PyPDF2py-pdf PyPDF2 46 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.