Technology · PyPI
pypdf (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 44 vulnerabilities in pypdf (PyPI): 0 in the last 7 days and 33 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-84311, was published on 1 September 2026.
- Last 7 days
- 0
- Last 90 days
- 33
- Critical, all time
- 0
- Exploited in the wild
- 0
About pypdf (PyPI)
A pure Python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files.
Latest pypdf (PyPI) vulnerabilities
- CVE-2026-84311: pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes…mediumCVSS 4EPSS 0.2%
- CVE-2026-84310: pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes…mediumCVSS 4EPSS 0.2%
- CVE-2026-84309: pypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cyclic tree…mediumCVSS 4EPSS 0.2%
- CVE-2026-82398: pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long…mediumCVSS 4EPSS 0.5%
- CVE-2026-71870: pypdf uncontrolled resource consumption in ToUnicode streamsmediumCVSS 4EPSS 0.2%
- CVE-2026-71852: pypdf excessive iteration in CID font width parsingmediumCVSS 4EPSS 0.2%
- CVE-2026-41314: PYSEC-2026-3026 - pypdf: Manipulated FlateDecode image dimensions can exhaust RAMlowCVSS 3.1EPSS 0.4%
- CVE-2026-41313: PYSEC-2026-3007 - pypdf: Possible long runtimes for wrong size values in incremental modelowCVSS 3.1EPSS 0.4%
- CVE-2026-41312: PYSEC-2026-3011 - pypdf: Manipulated FlateDecode predictor parameters can exhaust RAMlowCVSS 3.1EPSS 0.4%
- CVE-2026-33699: PYSEC-2026-3012 - pypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_streammediumCVSS 4EPSS 0.6%
- CVE-2026-33123: PYSEC-2026-3023 - pypdf has inefficient decoding of array-based streamsmediumCVSS 4EPSS 0.4%
- CVE-2026-31826: PYSEC-2026-3019 - pypdf: manipulated stream length values can exhaust RAMmediumCVSS 4EPSS 0.2%
- CVE-2026-28804: PYSEC-2026-3014 - pypdf vulnerable to inefficient decoding of ASCIIHexDecode streamsmediumCVSS 4EPSS 0.5%
- CVE-2026-28351: PYSEC-2026-3017 - pypdf: Manipulated RunLengthDecode streams can exhaust RAMmediumCVSS 4EPSS 0.5%
- CVE-2026-27888: PYSEC-2026-3027 - pypdf: Manipulated FlateDecode XFA streams can exhaust RAMmediumCVSS 4EPSS 0.6%
- CVE-2026-27628: PYSEC-2026-3005 - pypdf has a possible infinite loop when loading circular /Prev entries in cross-reference streamsmediumCVSS 4EPSS 0.6%
- CVE-2026-27026: PYSEC-2026-3015 - pypdf possibly has long runtimes for malformed FlateDecode streamsmediumCVSS 4EPSS 0.2%
- CVE-2026-27025: PYSEC-2026-3024 - pypdf has possible long runtimes/large memory usage for large /ToUnicode streamsmediumCVSS 4EPSS 0.2%
- CVE-2026-27024: PYSEC-2026-3013 - pypdf has a possible infinite loop when processing TreeObjectmediumCVSS 4EPSS 0.2%
- CVE-2023-36464: PYSEC-2026-3008 - pypdf and PyPDF2 possible Infinite Loop when a comment isn't followed by a characterlowCVSS 3.1EPSS 0.4%
- CVE-2026-59936: py-pdf pypdf infinite loop in inline image parsinghighCVSS 4EPSS 0.6%
- CVE-2026-59935: py-pdf pypdf infinite loop in inline image parsinghighCVSS 4EPSS 0.6%
- CVE-2026-59938: py-pdf pypdf excessive memory allocation in image parsingmediumCVSS 4EPSS 0.5%
- CVE-2026-59937: py-pdf pypdf resource consumption via malformed xref streamsmediumCVSS 4EPSS 0.6%
- CVE-2026-24688: PYSEC-2026-1827 - pypdf has possible Infinite Loop when processing outlines/bookmarksmediumCVSS 4EPSS 0.4%
Most severe pypdf (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-59936: py-pdf pypdf infinite loop in inline image parsinghighCVSS 4EPSS 0.6%
- CVE-2026-59935: py-pdf pypdf infinite loop in inline image parsinghighCVSS 4EPSS 0.6%
- pypdf uncontrolled resource consumption in stream parsingmediumCVSS 6.9
- CVE-2026-41168: pypdf has long runtimes for wrong size values in cross-reference and object streamsmediumCVSS 5.3EPSS 0.5%
- CVE-2026-40260: pypdf: Manipulated XMP metadata entity declarations can exhaust RAMmediumCVSS 5.3EPSS 0.5%
- CVE-2026-27888: PYSEC-2026-3027 - pypdf: Manipulated FlateDecode XFA streams can exhaust RAMmediumCVSS 4EPSS 0.6%
- CVE-2026-59937: py-pdf pypdf resource consumption via malformed xref streamsmediumCVSS 4EPSS 0.6%
- CVE-2026-27628: PYSEC-2026-3005 - pypdf has a possible infinite loop when loading circular /Prev entries in cross-reference streamsmediumCVSS 4EPSS 0.6%
- CVE-2026-33699: PYSEC-2026-3012 - pypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_streammediumCVSS 4EPSS 0.6%
- CVE-2026-82398: pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long…mediumCVSS 4EPSS 0.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 1 | 0 | |
| 6 Jul 2026 | 12 | 0 | |
| 13 Jul 2026 | 14 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 2 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 4 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/pypdf.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "pypdf (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/pypdf, 26 September 2026.