VYPR

PyPI package

pypdf

pkg:pypi/pypdf

Vulnerabilities (24)

  • CVE-2025-62707Oct 22, 2025
    affected < 6.1.3fixed 6.1.3

    pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires parsing the content stream of a page which has an inline image using the DCTDecode filter. This

  • CVE-2025-55197Aug 13, 2025
    affected < 6.0.0fixed 6.0.0

    pypdf is a free and open-source pure-python PDF library. Prior to version 6.0.0, an attacker can craft a PDF which leads to the RAM being exhausted. This requires just reading the file if a series of FlateDecode filters is used on a malicious cross-reference stream. Other content

  • CVE-2023-46250Oct 31, 2023
    affected >= 3.7.0, < 3.17.0fixed 3.17.0

    pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions 3.7.0 through 3.16.4 can craft a PDF which leads to an infinite loop. This infinite loop blocks the current process and can utilize a single core of the CPU by 100%.

  • CVE-2023-36464Jun 27, 2023
    affected >= 3.1.0, < 3.9.0fixed 3.9.0

    pypdf is an open source, pure-python PDF library. In affected versions an attacker may craft a PDF which leads to an infinite loop if `__parse_content_stream` is executed. That is, for example, the case if the user extracted text from such a PDF. This issue was introduced in pull

Page 2 of 2