Vulnerabilidades en py-pdf
46 resultadosAnálisis Vexday
PyPDF registra 40 vulnerabilidades conhecidas sem nenhuma sob exploração ativa (KEV=0), reduzindo o risco imediato de ataques direcionados. A ausência de vulnerabilidades críticas (CVSS 9.0+) é positiva, porém 13 publicações nos últimos 90 dias indicam descoberta contínua de falhas; a fraqueza dominante é CWE-400 (Uncontrolled Resource Consumption), típica de negação de serviço. O ritmo recente de divulgações sugere que atualizações frequentes devem ser priorizadas para gestão da superfície de ataque.
CVE-2026-22691LOWpypdf has possible long runtimes for malformed startxrefEPSS 0.4%CVE-2026-41314MEDIUMpypdf: Manipulated FlateDecode image dimensions can exhaust RAMEPSS 0.4%CVE-2026-41312MEDIUMpypdf: Manipulated FlateDecode predictor parameters can exhaust RAMEPSS 0.4%CVE-2026-41313MEDIUMpypdf: Possible long runtimes for wrong size values in incremental modeEPSS 0.4%CVE-2026-33123MEDIUMpypdf has inefficient decoding of array-based streamsEPSS 0.4%CVE-2026-57204MEDIUMpypdf: Missing stream length values ignore defined limitsEPSS 0.4%CVE-2025-66019MEDIUMpypdf manipulated LZWDecode streams can exhaust RAMEPSS 0.4%CVE-2023-36464MEDIUMInfinite Loop when a comment isn't followed by a character in pypdfEPSS 0.4%CVE-2023-46250MEDIUMpypdf possible Infinite Loop when PdfWriter(clone_from) is used with a PDFEPSS 0.2%CVE-2026-27026MEDIUMpypdf possibly has long runtimes for malformed FlateDecode streamsEPSS 0.2%CVE-2026-27025MEDIUMpypdf has possible long runtimes/large memory usage for large /ToUnicode streamsEPSS 0.2%CVE-2026-27024MEDIUMpypdf has a possible infinite loop when processing TreeObjectEPSS 0.2%CVE-2026-84311MEDIUMpypdf: Possible long runtimes/large memory usage when extracting XForm objectsEPSS 0.2%CVE-2026-84310MEDIUMpypdf: Possible long runtimes/large memory usage when retrieving outlinesEPSS 0.2%CVE-2026-71852MEDIUMpypdf: Possible long runtimes/large memory usage for large CID font width rangesEPSS 0.2%CVE-2026-71870MEDIUMpypdf: Possible large memory usage for large /ToUnicode streamsEPSS 0.2%CVE-2026-48735MEDIUMpypdf: Manipulated XMP metadata streams can exhaust RAMEPSS 0.2%CVE-2026-84309MEDIUMpypdf: Possible infinite loop for TreeObject.insert_childEPSS 0.2%CVE-2026-48155MEDIUMpypdf: Possible large memory usage for large offsets for layout mode textEPSS 0.2%CVE-2026-31826MEDIUMpypdf: manipulated stream length values can exhaust RAMEPSS 0.2%