pypi package report

Is PyPDF2 safe?

4 known vulnerabilities, worst severity MODERATE.

cvss
6.2

how bad it is if exploited, out of 10

epss
0.40%

chance of exploitation in the next 30 days

xyz score
not scored

CyberXYZ composite, out of 10

fig. 01 — GHSA-4vvm-4w3v-6mr8, the advisory selected below

// advisories

GHSA-4vvm-4w3v-6mr8

MODERATECVE-2023-36464

An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop if parsecontentstream is executed. This infinite loop blocks the current process and can utilize a single core of the CPU by 100%. It does not affect memory usage. That is, for example, the case if the user extracted text from such a PDF.

Affected
>= 2.2.0, <= 3.0.1
Fixed in
not stated
Weakness
CWE-835
Published
2023-06-30
Source
github

GHSANVDMITREreferencereferencereferencereferencereference


// ai model usage

No published models are known to use this package.


Checked 2026-09-22 at 01:35 UTC. The most recent advisory here was published 2023-06-30. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is PyPDF2 safe? pypi package security report | CyberXYZ