Infinite Loop Vulnerability in pypdf Library by py-pdf
CVE-2026-84309

6.9MEDIUM

Key Information:

Vendor

Py-PDF

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-84309?

The pypdf library, a free and open-source PDF manipulation tool, contains a vulnerability that allows attackers to create malicious PDFs. These crafted files can induce pypdf’s TreeObject in the generic data structures module to enter an endless loop during specific code execution paths. This issue arises before version 6.16.0, where a poorly structured cyclic tree can cause the code to follow /Next links indefinitely while attempting to insert a child node. This flaw has been addressed in version 6.16.0.

Affected Version(s)

pypdf < 6.16.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.