6.10.2
11 years ago
11 days ago
Known vulnerabilities in the pyPdf package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
pypdf is an A pure-python PDF library capable of splitting, merging, cropping, and transforming PDF files Affected versions of this package are vulnerable to Improper Validation of Specified Quantity in Input through the How to fix Improper Validation of Specified Quantity in Input? Upgrade | [,6.10.1) |
pypdf is an A pure-python PDF library capable of splitting, merging, cropping, and transforming PDF files Affected versions of this package are vulnerable to Excessive Iteration in the incremental mode for PDF processing. An attacker can cause excessive resource consumption and significantly degrade performance by loading a PDF file with a large trailer How to fix Excessive Iteration? Upgrade | [,6.10.2) |
pypdf is an A pure-python PDF library capable of splitting, merging, cropping, and transforming PDF files Affected versions of this package are vulnerable to Memory Allocation with Excessive Size Value via the How to fix Memory Allocation with Excessive Size Value? Upgrade | [,6.10.2) |
pypdf is an A pure-python PDF library capable of splitting, merging, cropping, and transforming PDF files Affected versions of this package are vulnerable to Memory Allocation with Excessive Size Value in the How to fix Memory Allocation with Excessive Size Value? Upgrade | [,6.10.2) |
pypdf is an A pure-python PDF library capable of splitting, merging, cropping, and transforming PDF files Affected versions of this package are vulnerable to XML Entity Expansion when parsing XMP metadata. An attacker can cause excessive memory consumption with excessive DOCTYPE entity declarations. How to fix XML Entity Expansion? Upgrade | [,6.10.0) |
pypdf is an A pure-python PDF library capable of splitting, merging, cropping, and transforming PDF files Affected versions of this package are vulnerable to Infinite loop in the Note: This is only exploitable if non-strict mode is enabled. How to fix Infinite loop? Upgrade | [,6.9.2) |
pypdf is an A pure-python PDF library capable of splitting, merging, cropping, and transforming PDF files Affected versions of this package are vulnerable to Inefficient Algorithmic Complexity in the decoding process of array-based streams. An attacker can cause excessive resource consumption by crafting a PDF with a large number of entries in an array-based stream. How to fix Inefficient Algorithmic Complexity? Upgrade | [,6.9.1) |
pypdf is an A pure-python PDF library capable of splitting, merging, cropping, and transforming PDF files Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling in Note: The project maintainers note that "As far as we are aware, this mostly affects reading from buffers of unknown size, as returned by How to fix Allocation of Resources Without Limits or Throttling? Upgrade | [,6.8.0) |
pypdf is an A pure-python PDF library capable of splitting, merging, cropping, and transforming PDF files Affected versions of this package are vulnerable to Inefficient Algorithmic Complexity due to the inefficient decoding of ASCIIHexDecode streams. An attacker can cause excessive resource consumption and significantly degrade performance by crafting a PDF that triggers long runtimes in streams using the How to fix Inefficient Algorithmic Complexity? Upgrade | [,6.7.5) |