Security: py-pdf/pypdf
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Possible long runtimes for wrong size values in incremental modeGHSA-4pxv-j86v-mhcw published
Apr 15, 2026 by stefan6419846Moderate -
Manipulated FlateDecode image dimensions can exhaust RAMGHSA-x284-j5p8-9c5p published
Apr 15, 2026 by stefan6419846Moderate -
Possible long runtimes for wrong size values in cross-reference and object streamsGHSA-jj6c-8h6c-hppx published
Apr 14, 2026 by stefan6419846Moderate -
Manipulated XMP metadata entity declarations can exhaust RAMGHSA-3crg-w4f6-42mx published
Apr 10, 2026 by stefan6419846Moderate -
Possible infinite loop during recovery attempts in DictionaryObject.read_from_streamGHSA-87mj-5ggw-8qc3 published
Mar 23, 2026 by stefan6419846Moderate -
Inefficient decoding of array-based streamsGHSA-qpxp-75px-xjcp published
Mar 17, 2026 by stefan6419846Moderate -
Manipulated stream length values can exhaust RAMGHSA-hqmh-ppp3-xvm7 published
Mar 9, 2026 by stefan6419846Moderate -
Inefficient decoding of ASCIIHexDecode streamsGHSA-9m86-7pmv-2852 published
Mar 2, 2026 by stefan6419846Moderate -
Manipulated RunLengthDecode streams can exhaust RAMGHSA-f2v5-7jq9-h8cg published
Feb 27, 2026 by stefan6419846Moderate -
Manipulated FlateDecode XFA streams can exhaust RAMGHSA-x7hp-r3qg-r3cj published
Feb 24, 2026 by stefan6419846Moderate