Security: py-pdf/pypdf
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Missing stream length values ignore defined limitsGHSA-jm82-fx9c-mx94 published
Jun 17, 2026 by stefan6419846Moderate -
Possible infinite loop when processing threads/articles in writerGHSA-g9xf-7f8q-9mcj published
Jun 8, 2026 by stefan6419846Moderate -
Possible infinite loop when processing outlines/bookmarks in writerGHSA-m2v9-299j-rv96 published
Jun 5, 2026 by stefan6419846Moderate -
Possible infinite loop when retrieving fonts for layout-mode text extractionGHSA-52x6-gq3r-vpf4 published
Jun 5, 2026 by stefan6419846Moderate -
Possible large memory usage for form XObjects during text extractionGHSA-j543-4vmf-qm7v published
May 26, 2026 by stefan6419846Moderate -
Inefficient decoding of FlateDecode PNG predictor streamsGHSA-5hgr-hg42-57jg published
May 26, 2026 by stefan6419846Moderate -
Manipulated XMP metadata streams can exhaust RAMGHSA-wjqc-6w8f-h24c published
May 22, 2026 by stefan6419846Moderate -
Possible large memory usage for large offsets for layout mode textGHSA-cj93-chg6-vgv8 published
May 21, 2026 by stefan6419846Moderate -
Possible long runtimes for zero-only width values in cross-reference streamsGHSA-248m-82v9-q6g6 published
May 21, 2026 by stefan6419846Moderate -
Manipulated FlateDecode predictor parameters can exhaust RAMGHSA-7gw9-cf7v-778f published
Apr 15, 2026 by stefan6419846Moderate