The pypdf library has vulnerabilities that allow attackers to exploit PDF files and cause long runtimes or RAM exhaustion.
Claims
The pypdf library has vulnerabilities that allow attackers to exploit PDF files and cause long runtimes or RAM exhaustion.
Parent: Software VulnerabilitiesEntity: pypdf libraryImpact: negativeDate: Apr 23, 2026Target: The pypdf library's security
Source posts
๐จ EUVD-2026-25112
๐ Score: 4.8/10 (CVSS v3.1)
๐ฆ Product: pypdf
๐ข Vendor: py-pdf
๐
Updated: 2026-04-22
๐ pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to the RAM being exhausted. This requires accessing a stream compressed using `/FlateDecode` with a `/P...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25112
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-25114
๐ Score: 4.8/10 (CVSS v3.1)
๐ฆ Product: pypdf
๐ข Vendor: py-pdf
๐
Updated: 2026-04-22
๐ pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to long runtimes. This requires loading a PDF with a large trailer `/Size` value in incremental mode. T...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25114
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-25116
๐ Score: 4.8/10 (CVSS v3.1)
๐ฆ Product: pypdf
๐ข Vendor: py-pdf
๐
Updated: 2026-04-22
๐ pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to the RAM being exhausted. This requires accessing an image using `/FlateDecode` with large size value...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25116
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability