© 2025-2026 PySpect
First version without a known vulnerability: 6.15.0
pypdf: Possible large memory usage for large /ToUnicode streams
Fixed in: 6.15.0
pypdf: Possible long runtimes/large memory usage for large CID font width ranges
Fixed in: 6.15.0
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
Fixed in: 6.14.2
pypdf: Possible infinite loop for not terminated inline images
Fixed in: 6.14.1
pypdf: Possible long runtimes for repeated malformed cross-reference entries
Fixed in: 6.14.0
pypdf: Possible large memory usage for wrong image dimensions
Fixed in: 6.14.0
pypdf: Possible infinite loop when processing threads/articles in writer
Fixed in: 6.13.1
pypdf: Missing stream length values ignore defined limits
Fixed in: 6.13.3
pypdf: Possible infinite loop when processing outlines/bookmarks in writer
Fixed in: 6.13.0
pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction
Fixed in: 6.13.0
pypdf: Possible large memory usage for form XObjects during text extraction
Fixed in: 6.12.2
pypdf: Inefficient decoding of FlateDecode PNG predictor streams
Fixed in: 6.12.2
pypdf: Manipulated XMP metadata streams can exhaust RAM
Fixed in: 6.12.1
pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streams
Fixed in: 6.12.0
pypdf: Possible large memory usage for large offsets for layout mode text
Fixed in: 6.12.0
pypdf: Manipulated FlateDecode image dimensions can exhaust RAM
Fixed in: 6.10.2
pypdf: Possible long runtimes for wrong size values in incremental mode
Fixed in: 6.10.2
pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM
Fixed in: 6.10.2
pypdf has long runtimes for wrong size values in cross-reference and object streams
Fixed in: 6.10.1
pypdf: Manipulated XMP metadata entity declarations can exhaust RAM
Fixed in: 6.10.0
pypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_stream
Fixed in: 6.9.2
pypdf has inefficient decoding of array-based streams
Fixed in: 6.9.1
pypdf: manipulated stream length values can exhaust RAM
Fixed in: 6.8.0
pypdf vulnerable to inefficient decoding of ASCIIHexDecode streams
Fixed in: 6.7.5
pypdf: Manipulated RunLengthDecode streams can exhaust RAM
Fixed in: 6.7.4
pypdf: Manipulated FlateDecode XFA streams can exhaust RAM
Fixed in: 6.7.3
pypdf has a possible infinite loop when loading circular /Prev entries in cross-reference streams
Fixed in: 6.7.2
pypdf possibly has long runtimes for malformed FlateDecode streams
Fixed in: 6.7.1
pypdf has possible long runtimes/large memory usage for large /ToUnicode streams
Fixed in: 6.7.1
pypdf has a possible infinite loop when processing TreeObject
Fixed in: 6.7.1
pypdf has possible Infinite Loop when processing outlines/bookmarks
Fixed in: 6.6.2
pypdf has possible long runtimes for malformed startxref
Fixed in: 6.6.0
pypdf has possible long runtimes for missing /Root object with large /Size values
Fixed in: 6.6.0
pypdf's LZWDecode streams be manipulated to exhaust RAM
Fixed in: 6.4.0
pypdf can exhaust RAM via manipulated LZWDecode streams
Fixed in: 6.1.3
pypdf possibly loops infinitely when reading DCT inline images without EOF marker
Fixed in: 6.1.3
PyPDF's Manipulated FlateDecode streams can exhaust RAM
Fixed in: 6.0.0
Possible Infinite Loop when PdfWriter(clone_from) is used with a PDF
Fixed in: 3.17.0
pypdf and PyPDF2 possible Infinite Loop when a comment isn't followed by a character
Fixed in: 3.9.0