{"id":"PYSEC-2026-1871","summary":"Reportlab vulnerable to remote code execution","details":"Reportlab up to and including v3.6.12 allows attackers to execute arbitrary code via supplying a crafted PDF file.","aliases":["CVE-2023-33733","GHSA-9q9m-c65c-37pq"],"modified":"2026-07-07T17:47:34.451366344Z","published":"2026-07-07T11:45:19.111659Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-33733"},{"type":"WEB","url":"https://github.com/c53elyas/CVE-2023-33733"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/10/msg00008.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36WOY22ECJCPOXHVTNCHEWOQLL7JSWP4"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6ALE727IRACYBTTOFIFG57RS4OA2SHIJ"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/36WOY22ECJCPOXHVTNCHEWOQLL7JSWP4"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6ALE727IRACYBTTOFIFG57RS4OA2SHIJ"},{"type":"PACKAGE","url":"https://pypi.org/project/reportlab"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9q9m-c65c-37pq"}],"affected":[{"package":{"name":"reportlab","ecosystem":"PyPI","purl":"pkg:pypi/reportlab"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.13"}]}],"versions":["2.0","2.3","2.4","2.5","2.6","2.7","3.0","3.1.44","3.1.8","3.2.0","3.3.0","3.4.0","3.5.0","3.5.1","3.5.10","3.5.11","3.5.12","3.5.13","3.5.16","3.5.17","3.5.18","3.5.19","3.5.2","3.5.20","3.5.21","3.5.23","3.5.26","3.5.28","3.5.31","3.5.32","3.5.34","3.5.4","3.5.42","3.5.44","3.5.45","3.5.46","3.5.47","3.5.48","3.5.49","3.5.5","3.5.50","3.5.51","3.5.52","3.5.53","3.5.54","3.5.55","3.5.56","3.5.57","3.5.58","3.5.59","3.5.6","3.5.62","3.5.63","3.5.64","3.5.65","3.5.66","3.5.67","3.5.68","3.5.8","3.5.9","3.6.0","3.6.1","3.6.10","3.6.11","3.6.12","3.6.2","3.6.3","3.6.5","3.6.6","3.6.7","3.6.8","3.6.9"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/reportlab/PYSEC-2026-1871.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}