Pypdf is a widely used open-source PDF manipulation library with a narrow product scope but significant downstream reach through its integration into applications across multiple domains. The vendor's vulnerability footprint, while modest in raw count, concentrates in resource-exhaustion and algorithmic-complexity weaknesses—infinite loops, uncontrolled resource consumption, excessive iteration, and unbounded allocation—that arise from the library's PDF parsing and processing logic. These weakness classes reflect the inherent parsing complexity of the PDF specification and can amplify in risk when the library processes untrusted or maliciously crafted documents at scale. Defenders should monitor this library's releases closely and evaluate update cycles in the context of downstream products that embed it, since remediation may depend on those projects rebuilding and redistributing their own packages. Current CVE counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pypdf Project over time
Signals from CVEs in this vendor scope (38 CVEs).
38 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-59936HIGH pypdf is a free and open-source pure-python PDF library. Prior to 6.14.1, an attacker can craft a PDF with a page content stream containing a not terminated inline image, causing a | Jul 8, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-59935HIGH pypdf is a free and open-source pure-python PDF library. Prior to 6.14.2, an attacker can craft a PDF with a page content stream containing a not terminated inline image that uses | Jul 8, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-59937HIGH pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with repeated malformed cross-reference streams that cause pypdf to spend long | Jul 8, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-57204MEDIUM pypdf is a free and open-source pure-python PDF library. Prior to 6.13.3, a maliciously crafted PDF can cause DoS. An attacker who uses this vulnerability can craft a PDF which lea | Jun 30, 2026 | 6.5 | 29 | NO | NO |
CVE-2026-59938MEDIUM pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with declared image size values that are much too large compared to the actual | Jul 8, 2026 | 5.3 | 26 | NO | NO |
CVE-2026-27888HIGH pypdf is a free and open-source pure-python PDF library. Prior to 6.7.3, an attacker who uses this vulnerability can craft a PDF which leads to the RAM being exhausted. This requir | Feb 26, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-27628HIGH pypdf is a free and open-source pure-python PDF library. Prior to 6.7.2, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires read | Feb 25, 2026 | 7.5 | 26 | NO | NO |
CVE-2025-55197HIGH pypdf is a free and open-source pure-python PDF library. Prior to version 6.0.0, an attacker can craft a PDF which leads to the RAM being exhausted. This requires just reading the | Aug 13, 2025 | 7.5 | 26 | NO | NO |
CVE-2026-33699HIGH pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.2 have a vulnerability in which an attacker can craft a PDF which leads to an infinite loop. This req | Mar 27, 2026 | 7.5 | 25 | NO | NO |
CVE-2025-62708HIGH pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This req | Oct 22, 2025 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (38 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pypdf Project.
Media articles that mention a CVE ID that affects a product developed by Pypdf Project — matched by CVE ID, not by vendor name.