{"id":"CVE-2026-84309","title":"pypdf is a free and open-source pure-python PDF library","summary":"pypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cyclic tree structure causes pypdf/generic/_data_structures.py TreeObject.insert_child to follow /Next links indefinitely when a …","severity":"medium","cwe":["CWE-835"],"vendor":"pypdf","product":"pypdf","affected":["pypdf < 6.16.0"],"patched":["pypdf 6.16.0"],"published":"2026-09-01","updated":"2026-09-09","sourceUpdated":"2026-09-09T16:49:20.627","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-84309","references":[{"url":"https://github.com/py-pdf/pypdf/commit/c9ba557d565d57c53a0b3a0be06c0a4c29b0559b","label":"security-advisories@github.com"},{"url":"https://github.com/py-pdf/pypdf/pull/3964","label":"security-advisories@github.com"},{"url":"https://github.com/py-pdf/pypdf/releases/tag/6.16.0","label":"security-advisories@github.com"},{"url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-jp53-mhqp-8xcg","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-jp53-mhqp-8xcg"},{"url":"https://github.com/py-pdf/pypdf"},{"url":"https://pypi.org/project/pypdf"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84309"}],"tags":["nvd","ghsa","pip","osv"],"epss":0.00127,"epssPercentile":0.02693,"aliases":["GHSA-jp53-mhqp-8xcg","PYSEC-2026-3913"],"ecosystem":"pip","ingestedAt":"2026-09-01T21:32:41.514Z","slug":"CVE-2026-84309","body":"## Overview\n\npypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cyclic tree structure causes pypdf/generic/_data_structures.py TreeObject.insert_child to follow /Next links indefinitely when a writing code path inserts a child, producing an infinite loop. This issue is fixed in version 6.16.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-84309)\n\nAffected packages:\n\n- `pypdf < 6.16.0`\n\nPatched in:\n\n- `pypdf 6.16.0`\n\nSource: https://github.com/advisories/GHSA-jp53-mhqp-8xcg","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}