Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2577▼ 295 respecto a la semana anterior
Críticas / altas1354▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
54 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Alta (8.7) | 0.30% | — | PypdfAI | 30/9/2026 | 1/10/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF can provide unusually large alphabetical page-label values that cause pypdf/_page_labels.py to generate strings beyond a reasonable page-label length when an application retrieves document page labels, consuming excessive memory… | |
| En análisis | Alta (8.7) | 0.30% | — | PypdfAI | 30/9/2026 | 1/10/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF containing many embedded files can cause the dictionary-based attachments API in pypdf/_doc_common.py to reparse the full attachment list for each content lookup, producing repeated work and long runtimes when an application… | |
| En análisis | Alta (8.7) | 0.30% | — | PypdfAI | 30/9/2026 | 1/10/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF with form field values can cause pypdf/generic/_appearance_stream.py appearance-stream generation to repeat invariant selection-data work inside a loop when an application updates fields with flattening enabled, resulting in… | |
| En análisis | Alta (8.7) | 0.30% | — | PypdfAI | 30/9/2026 | 2/10/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF containing a partially malformed /FlateDecode stream with padded data can force pypdf/filters.py to use inefficient byte-by-byte decompression while the earlier recovery counter fails to advance for bytes that successfully decode,… | |
| En análisis | Alta (8.7) | 0.30% | — | PypdfAI | 30/9/2026 | 1/10/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can provide a TrueType or Type1 simple font with an unusually large /Widths array, causing pypdf/_font.py Font._collect_tt_t1_character_widths to process entries beyond the 256 character codes meaningful for a simple font and… | |
| En análisis | Alta (8.7) | 0.30% | — | PypdfAI | 30/9/2026 | 1/10/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can place unusually large source-code or destination-string tokens in a font /ToUnicode mapping, causing pypdf/_cmap.py parse_bfchar to decode and retain oversized values during operations such as text extraction and consume… | |
| En análisis | Alta (8.7) | 0.30% | — | PypdfAI | 30/9/2026 | 1/10/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.18.0, a crafted PDF containing indirect-object identifiers or generation-number tokens that continue for a long time without whitespace can cause pypdf/_reader.py and pypdf/generic/_base.py to scan excessive input through read_until_whitespace,… | |
| Analizada | Alta (8.7) | 0.35% | — | Pypdf Project Pypdf | 30/9/2026 | 2/10/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an application retrieves document page labels, consuming large amounts of memory and… | |
| Pendiente de análisis | Media (4.8) | 0.18% | — | PypdfAI | 1/9/2026 | 9/9/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_page.py PageObject._extract_text and PageObject.extract_xform_text to traverse a directed acyclic graph of reused form XObjects in which each form invokes a child multiple times, creating… | |
| Pendiente de análisis | Media (4.8) | 0.18% | — | PypdfAI | 1/9/2026 | 9/9/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consume long runtimes and large amounts of memory when retrieving document outlines with large numbers of entries or deeply nested reused paths because the traversal… | |
| Pendiente de análisis | Media (6.9) | 0.18% | — | PypdfAI | 1/9/2026 | 9/9/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cyclic tree structure causes pypdf/generic/_data_structures.py TreeObject.insert_child to follow /Next links indefinitely when a writing code path inserts a child, producing an infinite loop. This issue is fixed… | |
| Pendiente de análisis | Media (6.9) | 0.52% | — | PypdfAI | 31/8/2026 | 9/9/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtimes when the pypdf/_utils.py function read_until_whitespace reads a stream containing a long run of bytes without whitespace. The function repeatedly performs immutable bytes concatenation in a… | |
| Pendiente de análisis | Media (4.8) | 0.18% | — | PypdfAI | 7/8/2026 | 9/9/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumption when pypdf/_cmap.py function parse_bfrange parses unusually large source-code or destination-string tokens in a font /ToUnicode CMap during text extraction. This issue is fixed in 6.15.0. | |
| Pendiente de análisis | Media (4.8) | 0.18% | — | PypdfAI | 7/8/2026 | 10/9/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause long runtimes and large memory consumption when pypdf/_font.py function Font._collect_cid_character_widths expands unusually large CID font /W width ranges or excessive width entries during text extraction. This issue is… | |
| Analizada | Alta (8.7) | 0.62% | — | Pypdf Project Pypdf | 8/7/2026 | 9/7/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.14.1, an attacker can craft a PDF with a page content stream containing a not terminated inline image, causing an infinite loop during inline image end marker detection such as when extracting page text. This issue is fixed in version 6.14.1. | |
| Analizada | Alta (8.7) | 0.62% | — | Pypdf Project Pypdf | 8/7/2026 | 9/7/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.14.2, an attacker can craft a PDF with a page content stream containing a not terminated inline image that uses the ASCII85 or ASCIIHex filters, causing an infinite loop during parsing such as when extracting page text. This issue is fixed in version… | |
| Analizada | Media (6.9) | 0.52% | — | Pypdf Project Pypdf | 8/7/2026 | 9/7/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with declared image size values that are much too large compared to the actual data, causing large memory usage in pypdf image parsing. This issue is fixed in version 6.14.0. | |
| Analizada | Media (6.9) | 0.62% | — | Pypdf Project Pypdf | 8/7/2026 | 9/7/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with repeated malformed cross-reference streams that cause pypdf to spend long runtimes recovering broken cross-reference table entries. This issue is fixed in version 6.14.0. | |
| Analizada | Media (6.9) | 0.37% | — | Pypdf Project Pypdf | 30/6/2026 | 6/7/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.13.3, a maliciously crafted PDF can cause DoS. An attacker who uses this vulnerability can craft a PDF which leads to large memory usage, as MAX_DECLARED_STREAM_LENGTH is sometimes ignored. This requires parsing a content stream without a /Length… | |
| Analizada | Media (6.9) | 0.16% | — | Pypdf Project Pypdf | 22/6/2026 | 24/6/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.13.1, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with threads/articles into a writer. This vulnerability is fixed in 6.13.1. | |
| Analizada | Media (6.9) | 0.17% | — | Pypdf Project Pypdf | 22/6/2026 | 25/6/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with outlines into a writer. This vulnerability is fixed in 6.13.0. | |
| Analizada | Media (6.9) | 0.17% | — | Pypdf Project Pypdf | 22/6/2026 | 25/6/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires extracting the text in layout mode. This vulnerability is fixed in 6.13.0. | |
| Analizada | Media (6.9) | 0.17% | — | Pypdf Project Pypdf | 22/6/2026 | 25/6/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires extracting the text of a page which contains a form XObject with self-references. This vulnerability is fixed in 6.12.2. | |
| Analizada | Media (5.1) | 0.17% | — | Pypdf Project Pypdf | 22/6/2026 | 25/6/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /FlateDecode filter with a PNG predictor. This vulnerability is fixed in 6.12.2. | |
| Analizada | Media (6.9) | 0.18% | — | Pypdf Project Pypdf | 28/5/2026 | 17/6/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.12.1, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing large XMP metadata, possibly with lots of unnecessary elements. This vulnerability is fixed in 6.12.1. |