pypdf2@1.22 vulnerabilities

A pure-python PDF library capable of splitting, merging, cropping, and transforming PDF files

Direct Vulnerabilities

Known vulnerabilities in the pypdf2 package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Inefficient Algorithmic Complexity

PyPDF2 is an A pure-python PDF library capable of splitting, merging, cropping, and transforming PDF files

Affected versions of this package are vulnerable to Inefficient Algorithmic Complexity by crafting a PDF, leading to an unexpectedly long runtime when trying to read large files without xref marker. This quadratic runtime blocks the current process and can utilize a single CPU core by 100%.

Note: Exploiting this vulnerability does not affect memory usage.

How to fix Inefficient Algorithmic Complexity?

Upgrade PyPDF2 to version 1.27.9 or higher.

[,1.27.9)
  • M
Denial of Service (DoS)

PyPDF2 is an A pure-python PDF library capable of splitting, merging, cropping, and transforming PDF files

Affected versions of this package are vulnerable to Denial of Service (DoS). An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop if __parse_content_stream is executed. This infinite loop blocks the current process and can utilize a single core of the CPU by 100%. It does not affect memory usage.

How to fix Denial of Service (DoS)?

There is no fixed version for PyPDF2.

[0,)
  • H
Denial of Service (DoS)

PyPDF2 is an A pure-python PDF library capable of splitting, merging, cropping, and transforming PDF files

Affected versions of this package are vulnerable to Denial of Service (DoS) due to invalid object. Exploiting this vulnerability is possible when reading the metadata.

How to fix Denial of Service (DoS)?

Upgrade PyPDF2 to version 2.10.6 or higher.

[,2.10.6)
  • M
Infinite loop

PyPDF2 is an A pure-python PDF library capable of splitting, merging, cropping, and transforming PDF files

Affected versions of this package are vulnerable to Infinite loop when trying to get the content stream of a crafted PDF.

How to fix Infinite loop?

Upgrade PyPDF2 to version 1.27.5 or higher.

[,1.27.5)