Vulnerabilidades en py-pdf

42 resultados
Análisis Vexday

PyPDF registra 40 vulnerabilidades conhecidas sem nenhuma sob exploração ativa (KEV=0), reduzindo o risco imediato de ataques direcionados. A ausência de vulnerabilidades críticas (CVSS 9.0+) é positiva, porém 13 publicações nos últimos 90 dias indicam descoberta contínua de falhas; a fraqueza dominante é CWE-400 (Uncontrolled Resource Consumption), típica de negação de serviço. O ritmo recente de divulgações sugere que atualizações frequentes devem ser priorizadas para gestão da superfície de ataque.

CVE-2026-59936HIGHpypdf: Possible infinite loop for not terminated inline imagesEPSS 0.3%CVE-2026-59938MEDIUMpypdf: Possible large memory usage for wrong image dimensionsEPSS 0.3%CVE-2026-41168MEDIUMpypdf has possible long runtimes for wrong size values in cross-reference and object streamsEPSS 0.3%CVE-2023-46250MEDIUMpypdf possible Infinite Loop when PdfWriter(clone_from) is used with a PDFEPSS 0.2%CVE-2026-41312MEDIUMpypdf: Manipulated FlateDecode predictor parameters can exhaust RAMEPSS 0.2%CVE-2026-41314MEDIUMpypdf: Manipulated FlateDecode image dimensions can exhaust RAMEPSS 0.2%CVE-2026-41313MEDIUMpypdf: Possible long runtimes for wrong size values in incremental modeEPSS 0.2%CVE-2026-57204MEDIUMpypdf: Missing stream length values ignore defined limitsEPSS 0.2%CVE-2026-31826MEDIUMpypdf: manipulated stream length values can exhaust RAMEPSS 0.2%CVE-2026-27024MEDIUMpypdf has a possible infinite loop when processing TreeObjectEPSS 0.2%CVE-2026-27025MEDIUMpypdf has possible long runtimes/large memory usage for large /ToUnicode streamsEPSS 0.2%CVE-2026-27026MEDIUMpypdf possibly has long runtimes for malformed FlateDecode streamsEPSS 0.2%CVE-2026-71870MEDIUMpypdf: Possible large memory usage for large /ToUnicode streamsEPSS 0.1%CVE-2026-48735MEDIUMpypdf: Manipulated XMP metadata streams can exhaust RAMEPSS 0.1%CVE-2026-48155MEDIUMpypdf: Possible large memory usage for large offsets for layout mode textEPSS 0.1%CVE-2026-71852MEDIUMpypdf: Possible long runtimes/large memory usage for large CID font width rangesEPSS 0.1%CVE-2026-48156MEDIUMpypdf: Possible long runtimes for zero-only width values in cross-reference streamsEPSS 0.1%CVE-2026-49461MEDIUMpypdf: Possible large memory usage for form XObjects during text extractionEPSS 0.1%CVE-2026-54531MEDIUMpypdf: Possible infinite loop when processing outlines/bookmarks in writerEPSS 0.1%CVE-2026-54530MEDIUMpypdf: Possible infinite loop when retrieving fonts for layout-mode text extractionEPSS 0.1%