Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pypdf Project

First CVE: Jun 27, 2023Active for: 3 yearsTotal CVEs: 38
24.2
VTI Score
Low

Pypdf is a widely used open-source PDF manipulation library with a narrow product scope but significant downstream reach through its integration into applications across multiple domains. The vendor's vulnerability footprint, while modest in raw count, concentrates in resource-exhaustion and algorithmic-complexity weaknesses—infinite loops, uncontrolled resource consumption, excessive iteration, and unbounded allocation—that arise from the library's PDF parsing and processing logic. These weakness classes reflect the inherent parsing complexity of the PDF specification and can amplify in risk when the library processes untrusted or maliciously crafted documents at scale. Defenders should monitor this library's releases closely and evaluate update cycles in the context of downstream products that embed it, since remediation may depend on those projects rebuilding and redistributing their own packages. Current CVE counts, severity distribution, and exploitation activity are shown alongside this summary.

FAUCET AI Generated
38
Total CVEs
More Total CVEs than 98% of tracked vendors
12.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pypdf Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 27, 2023
3 years ago
Most Recent CVE
Jul 8, 2026
16 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (38 CVEs).

38 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-59936HIGH
pypdf is a free and open-source pure-python PDF library. Prior to 6.14.1, an attacker can craft a PDF with a page content stream containing a not terminated inline image, causing a
Jul 8, 20267.533NONO
CVE-2026-59935HIGH
pypdf is a free and open-source pure-python PDF library. Prior to 6.14.2, an attacker can craft a PDF with a page content stream containing a not terminated inline image that uses
Jul 8, 20267.533NONO
CVE-2026-59937HIGH
pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with repeated malformed cross-reference streams that cause pypdf to spend long
Jul 8, 20267.532NONO
CVE-2026-57204MEDIUM
pypdf is a free and open-source pure-python PDF library. Prior to 6.13.3, a maliciously crafted PDF can cause DoS. An attacker who uses this vulnerability can craft a PDF which lea
Jun 30, 20266.529NONO
CVE-2026-59938MEDIUM
pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with declared image size values that are much too large compared to the actual
Jul 8, 20265.326NONO
CVE-2026-27888HIGH
pypdf is a free and open-source pure-python PDF library. Prior to 6.7.3, an attacker who uses this vulnerability can craft a PDF which leads to the RAM being exhausted. This requir
Feb 26, 20267.526NONO
CVE-2026-27628HIGH
pypdf is a free and open-source pure-python PDF library. Prior to 6.7.2, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires read
Feb 25, 20267.526NONO
CVE-2025-55197HIGH
pypdf is a free and open-source pure-python PDF library. Prior to version 6.0.0, an attacker can craft a PDF which leads to the RAM being exhausted. This requires just reading the
Aug 13, 20257.526NONO
CVE-2026-33699HIGH
pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.2 have a vulnerability in which an attacker can craft a PDF which leads to an infinite loop. This req
Mar 27, 20267.525NONO
CVE-2025-62708HIGH
pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This req
Oct 22, 20257.525NONO
View all 38 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products38 CVEs
71%
24%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local14 (36.8%)
Network24 (63.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low38 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None25 (65.8%)
Unknown0 (0.0%)
Required13 (34.2%)
Privileges Required
Low8 (21.1%)
High0 (0.0%)
None30 (78.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (38 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pypdf Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pypdf Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pypdf Project's Products

View all 1 CNAs →

Top CWEs