pypdf is vulnerable to Denial of Service (DoS)
48
Medium Risk
pypdf parses /ToUnicode CMap streams when extracting text from a PDF. A crafted font can provide /ToUnicode entries with unusually large token values. Processing these entries consumes excessive memory while building the character map. The fix limits the token length accepted for /ToUnicode entries.
You are affected if you are using a version that falls within the vulnerable range and you extract text from PDF documents whose embedded fonts can carry an untrusted /ToUnicode CMap.
pypdf is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 6.14.2.
Upgrade the pypdf library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant