pypdf@5.7.0 vulnerabilities

A pure-python PDF library capable of splitting, merging, cropping, and transforming PDF files

  • latest version

    6.0.0

  • latest non vulnerable version

  • first published

    11 years ago

  • latest version published

    6 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the pypdf package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Allocation of Resources Without Limits or Throttling

    pypdf is an A pure-python PDF library capable of splitting, merging, cropping, and transforming PDF files

    Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling due to the decompressed size for the FlateDecode filter. An attacker can cause excessive memory consumption by providing a crafted PDF file containing a series of malicious filters or cross-reference streams.

    Note: This is exploitable if the file is read and the affected streams are processed.

    How to fix Allocation of Resources Without Limits or Throttling?

    Upgrade pypdf to version 6.0.0 or higher.

    [,6.0.0)