CVE-2026-84309

NONE
CVSS v3
CVSS v2
EPSS (exploit probability)
CWE-835CWE

Description

pypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cyclic tree structure causes pypdf/generic/_data_structures.py TreeObject.insert_child to follow /Next links indefinitely when a writing code path inserts a child, producing an infinite loop. This issue is fixed in version 6.16.0.

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references