{"schema_version":1,"title":"pypdf (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 44 vulnerabilities in pypdf (PyPI): 0 in the last 7 days and 33 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-84311, was published on 1 September 2026.","url":"https://junglewise.ai/threats/technologies/pypdf","json_url":"https://junglewise.ai/threats/technologies/pypdf.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/pypdf","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":2,"all_time":44,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":4,"last_90_days":33,"last_365_days":44},"latest":[{"cve":"CVE-2026-84311","cvss":4,"epss":0.0018,"slug":"cve-2026-84311-pypdf-denial-of-service-via-crafted-xform-objects","title":"pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_page.py PageObject.","severity":"medium","exploited":false,"published_at":"2026-09-01T21:18:46.887+00:00","url":"https://junglewise.ai/threats/cve-2026-84311-pypdf-denial-of-service-via-crafted-xform-objects"},{"cve":"CVE-2026-84310","cvss":4,"epss":0.0018,"slug":"cve-2026-84310-pypdf-denial-of-service-via-malicious-pdf-outlines","title":"pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_","severity":"medium","exploited":false,"published_at":"2026-09-01T21:18:46.74+00:00","url":"https://junglewise.ai/threats/cve-2026-84310-pypdf-denial-of-service-via-malicious-pdf-outlines"},{"cve":"CVE-2026-84309","cvss":4,"epss":0.0018,"slug":"cve-2026-84309-pypdf-infinite-loop-in-treeobject-insert-child","title":"pypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cyclic tree structure causes pyp","severity":"medium","exploited":false,"published_at":"2026-09-01T20:17:25.027+00:00","url":"https://junglewise.ai/threats/cve-2026-84309-pypdf-infinite-loop-in-treeobject-insert-child"},{"cve":"CVE-2026-82398","cvss":4,"epss":0.0052,"slug":"cve-2026-82398-pypdf-inefficient-handling-of-non-whitespace-inputs-in-read-until","title":"pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtimes when the pyp","severity":"medium","exploited":false,"published_at":"2026-08-31T22:17:23.083+00:00","url":"https://junglewise.ai/threats/cve-2026-82398-pypdf-inefficient-handling-of-non-whitespace-inputs-in-read-until"},{"cve":"CVE-2026-71870","cvss":4,"epss":0.0018,"slug":"cve-2026-71870-pypdf-uncontrolled-resource-consumption-in-tounicode-streams","title":"pypdf uncontrolled resource consumption in ToUnicode streams","severity":"medium","exploited":false,"published_at":"2026-08-07T19:29:09+00:00","url":"https://junglewise.ai/threats/cve-2026-71870-pypdf-uncontrolled-resource-consumption-in-tounicode-streams"},{"cve":"CVE-2026-71852","cvss":4,"epss":0.0018,"slug":"cve-2026-71852-pypdf-excessive-iteration-in-cid-font-width-parsing","title":"pypdf excessive iteration in CID font width parsing","severity":"medium","exploited":false,"published_at":"2026-08-07T18:54:00+00:00","url":"https://junglewise.ai/threats/cve-2026-71852-pypdf-excessive-iteration-in-cid-font-width-parsing"},{"cve":"CVE-2026-41314","cvss":3.1,"epss":0.0041,"slug":"cve-2026-41314-pypdf-manipulated-flatedecode-image-dimensions-can-exhaust-ram","title":"PYSEC-2026-3026 - pypdf: Manipulated FlateDecode image dimensions can exhaust RAM","severity":"low","exploited":false,"published_at":"2026-07-13T15:02:49.272635+00:00","url":"https://junglewise.ai/threats/cve-2026-41314-pypdf-manipulated-flatedecode-image-dimensions-can-exhaust-ram"},{"cve":"CVE-2026-41313","cvss":3.1,"epss":0.0038,"slug":"cve-2026-41313-pypdf-possible-long-runtimes-for-wrong-size-values-in-incremental","title":"PYSEC-2026-3007 - pypdf: Possible long runtimes for wrong size values in incremental mode","severity":"low","exploited":false,"published_at":"2026-07-13T15:02:49.213004+00:00","url":"https://junglewise.ai/threats/cve-2026-41313-pypdf-possible-long-runtimes-for-wrong-size-values-in-incremental"},{"cve":"CVE-2026-41312","cvss":3.1,"epss":0.0041,"slug":"cve-2026-41312-pypdf-manipulated-flatedecode-predictor-parameters-can-exhaust","title":"PYSEC-2026-3011 - pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM","severity":"low","exploited":false,"published_at":"2026-07-13T15:02:49.156225+00:00","url":"https://junglewise.ai/threats/cve-2026-41312-pypdf-manipulated-flatedecode-predictor-parameters-can-exhaust"},{"cve":"CVE-2026-33699","cvss":4,"epss":0.0058,"slug":"cve-2026-33699-pypdf-possible-infinite-loop-during-recovery-attempts-in","title":"PYSEC-2026-3012 - pypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_stream","severity":"medium","exploited":false,"published_at":"2026-07-13T14:36:44.693643+00:00","url":"https://junglewise.ai/threats/cve-2026-33699-pypdf-possible-infinite-loop-during-recovery-attempts-in"},{"cve":"CVE-2026-33123","cvss":4,"epss":0.0037,"slug":"cve-2026-33123-pypdf-has-inefficient-decoding-of-array-based-streams","title":"PYSEC-2026-3023 - pypdf has inefficient decoding of array-based streams","severity":"medium","exploited":false,"published_at":"2026-07-13T14:36:43.403058+00:00","url":"https://junglewise.ai/threats/cve-2026-33123-pypdf-has-inefficient-decoding-of-array-based-streams"},{"cve":"CVE-2026-31826","cvss":4,"epss":0.0018,"slug":"cve-2026-31826-pypdf-manipulated-stream-length-values-can-exhaust-ram","title":"PYSEC-2026-3019 - pypdf: manipulated stream length values can exhaust RAM","severity":"medium","exploited":false,"published_at":"2026-07-13T14:36:42.160674+00:00","url":"https://junglewise.ai/threats/cve-2026-31826-pypdf-manipulated-stream-length-values-can-exhaust-ram"},{"cve":"CVE-2026-28804","cvss":4,"epss":0.0052,"slug":"cve-2026-28804-pypdf-vulnerable-to-inefficient-decoding-of-asciihexdecode","title":"PYSEC-2026-3014 - pypdf vulnerable to inefficient decoding of ASCIIHexDecode streams","severity":"medium","exploited":false,"published_at":"2026-07-13T14:36:40.337454+00:00","url":"https://junglewise.ai/threats/cve-2026-28804-pypdf-vulnerable-to-inefficient-decoding-of-asciihexdecode"},{"cve":"CVE-2026-28351","cvss":4,"epss":0.0052,"slug":"cve-2026-28351-pypdf-manipulated-runlengthdecode-streams-can-exhaust-ram","title":"PYSEC-2026-3017 - pypdf: Manipulated RunLengthDecode streams can exhaust RAM","severity":"medium","exploited":false,"published_at":"2026-07-13T14:36:39.662772+00:00","url":"https://junglewise.ai/threats/cve-2026-28351-pypdf-manipulated-runlengthdecode-streams-can-exhaust-ram"},{"cve":"CVE-2026-27888","cvss":4,"epss":0.0064,"slug":"cve-2026-27888-pypdf-manipulated-flatedecode-xfa-streams-can-exhaust-ram","title":"PYSEC-2026-3027 - pypdf: Manipulated FlateDecode XFA streams can exhaust RAM","severity":"medium","exploited":false,"published_at":"2026-07-13T14:36:39.337929+00:00","url":"https://junglewise.ai/threats/cve-2026-27888-pypdf-manipulated-flatedecode-xfa-streams-can-exhaust-ram"},{"cve":"CVE-2026-27628","cvss":4,"epss":0.0061,"slug":"cve-2026-27628-pypdf-infinite-loop-in-circular-cross-reference-streams","title":"PYSEC-2026-3005 - pypdf has a possible infinite loop when loading circular /Prev entries in cross-reference streams","severity":"medium","exploited":false,"published_at":"2026-07-13T14:36:38.370166+00:00","url":"https://junglewise.ai/threats/cve-2026-27628-pypdf-infinite-loop-in-circular-cross-reference-streams"},{"cve":"CVE-2026-27026","cvss":4,"epss":0.0018,"slug":"cve-2026-27026-pypdf-possibly-has-long-runtimes-for-malformed-flatedecode","title":"PYSEC-2026-3015 - pypdf possibly has long runtimes for malformed FlateDecode streams","severity":"medium","exploited":false,"published_at":"2026-07-13T14:36:36.89312+00:00","url":"https://junglewise.ai/threats/cve-2026-27026-pypdf-possibly-has-long-runtimes-for-malformed-flatedecode"},{"cve":"CVE-2026-27025","cvss":4,"epss":0.0018,"slug":"cve-2026-27025-pypdf-has-possible-long-runtimes-large-memory-usage-for-large","title":"PYSEC-2026-3024 - pypdf has possible long runtimes/large memory usage for large /ToUnicode streams","severity":"medium","exploited":false,"published_at":"2026-07-13T14:36:36.833241+00:00","url":"https://junglewise.ai/threats/cve-2026-27025-pypdf-has-possible-long-runtimes-large-memory-usage-for-large"},{"cve":"CVE-2026-27024","cvss":4,"epss":0.0018,"slug":"cve-2026-27024-pypdf-has-a-possible-infinite-loop-when-processing-treeobject","title":"PYSEC-2026-3013 - pypdf has a possible infinite loop when processing TreeObject","severity":"medium","exploited":false,"published_at":"2026-07-13T14:36:36.769522+00:00","url":"https://junglewise.ai/threats/cve-2026-27024-pypdf-has-a-possible-infinite-loop-when-processing-treeobject"},{"cve":"CVE-2023-36464","cvss":3.1,"epss":0.0035,"slug":"cve-2023-36464-pypdf-and-pypdf2-possible-infinite-loop-when-a-comment-isn-t","title":"PYSEC-2026-3008 - pypdf and PyPDF2 possible Infinite Loop when a comment isn't followed by a character","severity":"low","exploited":false,"published_at":"2026-07-13T14:20:01.43033+00:00","url":"https://junglewise.ai/threats/cve-2023-36464-pypdf-and-pypdf2-possible-infinite-loop-when-a-comment-isn-t"},{"cve":"CVE-2026-59936","cvss":4,"epss":0.0062,"slug":"cve-2026-59936-py-pdf-pypdf-infinite-loop-in-inline-image-parsing","title":"py-pdf pypdf infinite loop in inline image parsing","severity":"high","exploited":false,"published_at":"2026-07-08T20:16:59.403+00:00","url":"https://junglewise.ai/threats/cve-2026-59936-py-pdf-pypdf-infinite-loop-in-inline-image-parsing"},{"cve":"CVE-2026-59935","cvss":4,"epss":0.0062,"slug":"cve-2026-59935-py-pdf-pypdf-infinite-loop-in-inline-image-parsing","title":"py-pdf pypdf infinite loop in inline image parsing","severity":"high","exploited":false,"published_at":"2026-07-08T20:16:59.26+00:00","url":"https://junglewise.ai/threats/cve-2026-59935-py-pdf-pypdf-infinite-loop-in-inline-image-parsing"},{"cve":"CVE-2026-59938","cvss":4,"epss":0.0052,"slug":"cve-2026-59938-py-pdf-pypdf-excessive-memory-allocation-in-image-parsing","title":"py-pdf pypdf excessive memory allocation in image parsing","severity":"medium","exploited":false,"published_at":"2026-07-08T18:16:35.097+00:00","url":"https://junglewise.ai/threats/cve-2026-59938-py-pdf-pypdf-excessive-memory-allocation-in-image-parsing"},{"cve":"CVE-2026-59937","cvss":4,"epss":0.0062,"slug":"cve-2026-59937-py-pdf-pypdf-resource-consumption-via-malformed-xref-streams","title":"py-pdf pypdf resource consumption via malformed xref streams","severity":"medium","exploited":false,"published_at":"2026-07-08T18:16:34.963+00:00","url":"https://junglewise.ai/threats/cve-2026-59937-py-pdf-pypdf-resource-consumption-via-malformed-xref-streams"},{"cve":"CVE-2026-24688","cvss":4,"epss":0.0045,"slug":"cve-2026-24688-pypdf-infinite-loop-in-outline-bookmark-processing","title":"PYSEC-2026-1827 - pypdf has possible Infinite Loop when processing outlines/bookmarks","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:20.675725+00:00","url":"https://junglewise.ai/threats/cve-2026-24688-pypdf-infinite-loop-in-outline-bookmark-processing"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":12},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":14},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"picklescan (PyPI)","slug":"picklescan","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/picklescan"},{"name":"openbabel (PyPI)","slug":"openbabel","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/openbabel"},{"name":"apache-superset (PyPI)","slug":"apache-superset","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/apache-superset"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"weblate (PyPI)","slug":"weblate","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/weblate"},{"name":"mcp-atlassian (PyPI)","slug":"mcp-atlassian","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/mcp-atlassian"},{"name":"crawl4ai (PyPI)","slug":"crawl4ai","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/crawl4ai"},{"name":"moin (PyPI)","slug":"moin","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/moin"}],"technology":{"hub":true,"name":"pypdf (PyPI)","slug":"pypdf","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://pypdf.readthedocs.io/","repo_url":"https://github.com/py-pdf/pypdf","description":"A pure Python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files.","url":"https://junglewise.ai/threats/technologies/pypdf"},"most_severe":[{"cve":"CVE-2026-59936","cvss":4,"epss":0.0062,"slug":"cve-2026-59936-py-pdf-pypdf-infinite-loop-in-inline-image-parsing","title":"py-pdf pypdf infinite loop in inline image parsing","severity":"high","exploited":false,"published_at":"2026-07-08T20:16:59.403+00:00","url":"https://junglewise.ai/threats/cve-2026-59936-py-pdf-pypdf-infinite-loop-in-inline-image-parsing"},{"cve":"CVE-2026-59935","cvss":4,"epss":0.0062,"slug":"cve-2026-59935-py-pdf-pypdf-infinite-loop-in-inline-image-parsing","title":"py-pdf pypdf infinite loop in inline image parsing","severity":"high","exploited":false,"published_at":"2026-07-08T20:16:59.26+00:00","url":"https://junglewise.ai/threats/cve-2026-59935-py-pdf-pypdf-infinite-loop-in-inline-image-parsing"},{"cvss":6.9,"slug":"pypdf-uncontrolled-resource-consumption-in-stream-parsing-aa3c6f57","title":"pypdf uncontrolled resource consumption in stream parsing","severity":"medium","exploited":false,"published_at":"2026-06-18T14:28:49+00:00","url":"https://junglewise.ai/threats/pypdf-uncontrolled-resource-consumption-in-stream-parsing-aa3c6f57"},{"cve":"CVE-2026-41168","cvss":5.3,"epss":0.0052,"slug":"cve-2026-41168-pypdf-has-long-runtimes-for-wrong-size-values-in-cross-reference","title":"pypdf has long runtimes for wrong size values in cross-reference and object streams","severity":"medium","exploited":false,"published_at":"2026-04-15T19:43:09+00:00","url":"https://junglewise.ai/threats/cve-2026-41168-pypdf-has-long-runtimes-for-wrong-size-values-in-cross-reference"},{"cve":"CVE-2026-40260","cvss":5.3,"epss":0.0052,"slug":"cve-2026-40260-pypdf-manipulated-xmp-metadata-entity-declarations-can-exhaust","title":"pypdf: Manipulated XMP metadata entity declarations can exhaust RAM","severity":"medium","exploited":false,"published_at":"2026-04-10T20:59:36+00:00","url":"https://junglewise.ai/threats/cve-2026-40260-pypdf-manipulated-xmp-metadata-entity-declarations-can-exhaust"},{"cve":"CVE-2026-27888","cvss":4,"epss":0.0064,"slug":"cve-2026-27888-pypdf-manipulated-flatedecode-xfa-streams-can-exhaust-ram","title":"PYSEC-2026-3027 - pypdf: Manipulated FlateDecode XFA streams can exhaust RAM","severity":"medium","exploited":false,"published_at":"2026-07-13T14:36:39.337929+00:00","url":"https://junglewise.ai/threats/cve-2026-27888-pypdf-manipulated-flatedecode-xfa-streams-can-exhaust-ram"},{"cve":"CVE-2026-59937","cvss":4,"epss":0.0062,"slug":"cve-2026-59937-py-pdf-pypdf-resource-consumption-via-malformed-xref-streams","title":"py-pdf pypdf resource consumption via malformed xref streams","severity":"medium","exploited":false,"published_at":"2026-07-08T18:16:34.963+00:00","url":"https://junglewise.ai/threats/cve-2026-59937-py-pdf-pypdf-resource-consumption-via-malformed-xref-streams"},{"cve":"CVE-2026-27628","cvss":4,"epss":0.0061,"slug":"cve-2026-27628-pypdf-infinite-loop-in-circular-cross-reference-streams","title":"PYSEC-2026-3005 - pypdf has a possible infinite loop when loading circular /Prev entries in cross-reference streams","severity":"medium","exploited":false,"published_at":"2026-07-13T14:36:38.370166+00:00","url":"https://junglewise.ai/threats/cve-2026-27628-pypdf-infinite-loop-in-circular-cross-reference-streams"},{"cve":"CVE-2026-33699","cvss":4,"epss":0.0058,"slug":"cve-2026-33699-pypdf-possible-infinite-loop-during-recovery-attempts-in","title":"PYSEC-2026-3012 - pypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_stream","severity":"medium","exploited":false,"published_at":"2026-07-13T14:36:44.693643+00:00","url":"https://junglewise.ai/threats/cve-2026-33699-pypdf-possible-infinite-loop-during-recovery-attempts-in"},{"cve":"CVE-2026-82398","cvss":4,"epss":0.0052,"slug":"cve-2026-82398-pypdf-inefficient-handling-of-non-whitespace-inputs-in-read-until","title":"pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtimes when the pyp","severity":"medium","exploited":false,"published_at":"2026-08-31T22:17:23.083+00:00","url":"https://junglewise.ai/threats/cve-2026-82398-pypdf-inefficient-handling-of-non-whitespace-inputs-in-read-until"}],"generated_at":"2026-09-26T13:07:00.120236+00:00"}