Vulnerabilidades em py-pdf

40 resultados
Análise Vexday

PyPDF registra 40 vulnerabilidades conhecidas sem nenhuma sob exploração ativa (KEV=0), reduzindo o risco imediato de ataques direcionados. A ausência de vulnerabilidades críticas (CVSS 9.0+) é positiva, porém 13 publicações nos últimos 90 dias indicam descoberta contínua de falhas; a fraqueza dominante é CWE-400 (Uncontrolled Resource Consumption), típica de negação de serviço. O ritmo recente de divulgações sugere que atualizações frequentes devem ser priorizadas para gestão da superfície de ataque.

CVE-2026-59937MEDIUMpypdf: Possible long runtimes for repeated malformed cross-reference entriesEPSS 0.3%CVE-2026-59938MEDIUMpypdf: Possible large memory usage for wrong image dimensionsEPSS 0.3%CVE-2026-41168MEDIUMpypdf has possible long runtimes for wrong size values in cross-reference and object streamsEPSS 0.3%CVE-2023-46250MEDIUMpypdf possible Infinite Loop when PdfWriter(clone_from) is used with a PDFEPSS 0.2%CVE-2026-41312MEDIUMpypdf: Manipulated FlateDecode predictor parameters can exhaust RAMEPSS 0.2%CVE-2026-41314MEDIUMpypdf: Manipulated FlateDecode image dimensions can exhaust RAMEPSS 0.2%CVE-2026-41313MEDIUMpypdf: Possible long runtimes for wrong size values in incremental modeEPSS 0.2%CVE-2026-57204MEDIUMpypdf: Missing stream length values ignore defined limitsEPSS 0.2%CVE-2026-31826MEDIUMpypdf: manipulated stream length values can exhaust RAMEPSS 0.2%CVE-2026-27025MEDIUMpypdf has possible long runtimes/large memory usage for large /ToUnicode streamsEPSS 0.2%CVE-2026-27024MEDIUMpypdf has a possible infinite loop when processing TreeObjectEPSS 0.2%CVE-2026-27026MEDIUMpypdf possibly has long runtimes for malformed FlateDecode streamsEPSS 0.2%CVE-2026-48735MEDIUMpypdf: Manipulated XMP metadata streams can exhaust RAMEPSS 0.1%CVE-2026-48155MEDIUMpypdf: Possible large memory usage for large offsets for layout mode textEPSS 0.1%CVE-2026-48156MEDIUMpypdf: Possible long runtimes for zero-only width values in cross-reference streamsEPSS 0.1%CVE-2026-54531MEDIUMpypdf: Possible infinite loop when processing outlines/bookmarks in writerEPSS 0.1%CVE-2026-49461MEDIUMpypdf: Possible large memory usage for form XObjects during text extractionEPSS 0.1%CVE-2026-54530MEDIUMpypdf: Possible infinite loop when retrieving fonts for layout-mode text extractionEPSS 0.1%CVE-2026-49460MEDIUMpypdf: Inefficient decoding of FlateDecode PNG predictor streamsEPSS 0.1%CVE-2026-54651MEDIUMpypdf: Possible infinite loop when processing threads/articles in writerEPSS 0.1%