Dependency scanning
Check whether pypdf is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-84311
pypdf: Possible long runtimes/large memory usage when extracting XForm objects
CVE-2026-82398
pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace
CVE-2026-84310
pypdf: Possible long runtimes/large memory usage when retrieving outlines
CVE-2026-84309
pypdf: Possible infinite loop for TreeObject.insert_child
CVE-2026-84309
pypdf: Possible infinite loop for TreeObject.insert_child
CVE-2026-84311
pypdf: Possible long runtimes/large memory usage when extracting XForm objects
CVE-2026-82398
pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace
CVE-2026-84310
pypdf: Possible long runtimes/large memory usage when retrieving outlines
CVE-2026-71870
pypdf: Possible large memory usage for large /ToUnicode streams
CVE-2026-71852
pypdf: Possible long runtimes/large memory usage for large CID font width ranges
CVE-2026-59936
pypdf: Possible infinite loop for not terminated inline images
CVE-2026-59938
pypdf: Possible large memory usage for wrong image dimensions
CVE-2026-54531
pypdf: Possible infinite loop when processing outlines/bookmarks in writer
CVE-2026-57204
pypdf: Missing stream length values ignore defined limits
CVE-2026-48155
pypdf: Possible large memory usage for large offsets for layout mode text
CVE-2026-48156
pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streams
CVE-2026-41314
pypdf: Manipulated FlateDecode image dimensions can exhaust RAM
CVE-2026-33123
pypdf has inefficient decoding of array-based streams
CVE-2026-33699
pypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_stream
CVE-2025-62707
pypdf possibly loops infinitely when reading DCT inline images without EOF marker
CVE-2026-59935
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
CVE-2026-54530
pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction
CVE-2026-41168
pypdf has long runtimes for wrong size values in cross-reference and object streams
CVE-2026-41312
pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM
CVE-2026-41313
pypdf: Possible long runtimes for wrong size values in incremental mode
CVE-2026-40260
pypdf: Manipulated XMP metadata entity declarations can exhaust RAM
CVE-2026-31826
pypdf: manipulated stream length values can exhaust RAM
CVE-2026-28804
pypdf vulnerable to inefficient decoding of ASCIIHexDecode streams
CVE-2026-27025
pypdf has possible long runtimes/large memory usage for large /ToUnicode streams
CVE-2026-28351
pypdf: Manipulated RunLengthDecode streams can exhaust RAM
CVE-2026-27026
pypdf possibly has long runtimes for malformed FlateDecode streams
CVE-2026-27024
pypdf has a possible infinite loop when processing TreeObject
CVE-2026-24688
pypdf has possible Infinite Loop when processing outlines/bookmarks
CVE-2025-66019
pypdf's LZWDecode streams be manipulated to exhaust RAM
CVE-2025-62708
pypdf can exhaust RAM via manipulated LZWDecode streams
CVE-2025-55197
PyPDF's Manipulated FlateDecode streams can exhaust RAM
CVE-2026-59937
pypdf: Possible long runtimes for repeated malformed cross-reference entries
CVE-2023-46250
Possible Infinite Loop when PdfWriter(clone_from) is used with a PDF
CVE-2023-36464
pypdf and PyPDF2 possible Infinite Loop when a comment isn't followed by a character
CVE-2026-71852
pypdf: Possible long runtimes/large memory usage for large CID font width ranges
CVE-2026-71870
pypdf: Possible large memory usage for large /ToUnicode streams
CVE-2026-59938
pypdf: Possible large memory usage for wrong image dimensions
CVE-2026-59936
pypdf: Possible infinite loop for not terminated inline images
CVE-2026-59937
pypdf: Possible long runtimes for repeated malformed cross-reference entries
CVE-2026-59935
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
CVE-2026-49461
pypdf: Possible large memory usage for form XObjects during text extraction
CVE-2026-27888
pypdf: Manipulated FlateDecode XFA streams can exhaust RAM
CVE-2026-27628
pypdf has a possible infinite loop when loading circular /Prev entries in cross-reference streams
CVE-2023-36464
pypdf and PyPDF2 possible Infinite Loop when a comment isn't followed by a character
CVE-2026-54651
pypdf: Possible infinite loop when processing threads/articles in writer
CVE-2026-48735
pypdf: Manipulated XMP metadata streams can exhaust RAM
CVE-2026-49460
pypdf: Inefficient decoding of FlateDecode PNG predictor streams
CVE-2026-27888
pypdf: Manipulated FlateDecode XFA streams can exhaust RAM
CVE-2026-41314
pypdf: Manipulated FlateDecode image dimensions can exhaust RAM
CVE-2026-27025
pypdf has possible long runtimes/large memory usage for large /ToUnicode streams
CVE-2026-48735
pypdf: Manipulated XMP metadata streams can exhaust RAM
CVE-2026-48155
pypdf: Possible large memory usage for large offsets for layout mode text
CVE-2026-28804
pypdf vulnerable to inefficient decoding of ASCIIHexDecode streams
CVE-2026-27026
pypdf possibly has long runtimes for malformed FlateDecode streams
CVE-2026-27024
pypdf has a possible infinite loop when processing TreeObject
CVE-2026-33699
pypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_stream
CVE-2026-49460
pypdf: Inefficient decoding of FlateDecode PNG predictor streams
CVE-2026-41312
pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM
CVE-2026-54530
pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction
CVE-2026-41313
pypdf: Possible long runtimes for wrong size values in incremental mode
CVE-2026-40260
pypdf: Manipulated XMP metadata entity declarations can exhaust RAM
CVE-2026-48156
pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streams
CVE-2026-27628
pypdf has a possible infinite loop when loading circular /Prev entries in cross-reference streams
CVE-2026-33123
pypdf has inefficient decoding of array-based streams
CVE-2026-49461
pypdf: Possible large memory usage for form XObjects during text extraction
CVE-2026-41168
pypdf has long runtimes for wrong size values in cross-reference and object streams
CVE-2026-54651
pypdf: Possible infinite loop when processing threads/articles in writer
CVE-2026-54531
pypdf: Possible infinite loop when processing outlines/bookmarks in writer
CVE-2026-28351
pypdf: Manipulated RunLengthDecode streams can exhaust RAM
CVE-2026-31826
pypdf: manipulated stream length values can exhaust RAM
CVE-2026-22690
pypdf has possible long runtimes for missing /Root object with large /Size values
CVE-2026-22691
pypdf has possible long runtimes for malformed startxref
CVE-2026-22691
pypdf has possible long runtimes for malformed startxref
CVE-2026-24688
pypdf has possible Infinite Loop when processing outlines/bookmarks
CVE-2023-46250
Possible Infinite Loop when PdfWriter(clone_from) is used with a PDF
CVE-2025-62707
pypdf possibly loops infinitely when reading DCT inline images without EOF marker
CVE-2025-66019
pypdf's LZWDecode streams be manipulated to exhaust RAM
CVE-2025-55197
PyPDF's Manipulated FlateDecode streams can exhaust RAM
CVE-2025-62708
pypdf can exhaust RAM via manipulated LZWDecode streams
CVE-2026-22690
pypdf has possible long runtimes for missing /Root object with large /Size values
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes