Skip to content

Security: py-pdf/pypdf

.github/SECURITY.md

Security Policy

Supported Versions

Security fixes are applied to the latest version.

Reporting a Vulnerability

If you find a potential security issue, please report it using the private vulnerability reporting feature of GitHub to automatically inform all relevant team members. Otherwise, please get in touch with stefan6419846 through e-mail (current maintainer, address in GitHub profile).

We will try to find a fix in a timely manner and then issue a security advisory together with the update via GitHub, as well as requesting a CVE (example).

If you do not get a reaction within 30 days, please open a public issue on GitHub.

Additional aspects to consider:

  • Please have a look at our corresponding user documentation, which includes some information about possibly invalid reports.
  • Respect our AI policy.
  • Reported issues we are unable to reproduce due to an invalid or missing proof-of-concept might be closed directly.
  • If you propose to add limits, please tell us which you would propose and why.
  • If you provide a fix, please make sure it is self-explanatory and can actually be executed.
  • Issues related to vulnerable OS or third-party libraries, as well as improper library usage from our users, are usually not considered security issues on our side.
Learn more about advisories related to py-pdf/pypdf in the GitHub Advisory Database