CVE-2026-84309
NONE—CVSS v3
—CVSS v2
—
EPSS (exploit probability)
CWE-835CWE
Description
pypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cyclic tree structure causes pypdf/generic/_data_structures.py TreeObject.insert_child to follow /Next links indefinitely when a writing code path inserts a child, producing an infinite loop. This issue is fixed in version 6.16.0.
Affected routers (0)
No routers currently mapped to this CVE in our database.