Pypdf2 is a Python library for reading and manipulating PDF files, with a vulnerability footprint centered on the single pypdf2 product and characterized by resource-control issues such as infinite loops in PDF parsing logic. The observed weakness class reflects the hazards of processing untrusted or malformed document formats without robust termination safeguards; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pypdf2 Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24859MEDIUM PyPDF2 is an open source python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files. In versions prior to 1.27.5 an attacker who uses this | Apr 18, 2022 | 5.5 | 21 | NO | NO |
CVE-2023-36464MEDIUM pypdf is an open source, pure-python PDF library. In affected versions an attacker may craft a PDF which leads to an infinite loop if `__parse_content_stream` is executed. That is, | Jun 27, 2023 | 5.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pypdf2 Project.
Media articles that mention a CVE ID that affects a product developed by Pypdf2 Project — matched by CVE ID, not by vendor name.