{"id":"CVE-2026-84310","title":"pypdf is a free and open-source pure-python PDF library","summary":"pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consume long runtimes and large amounts of memory when retrieving document outlines wi…","severity":"medium","cwe":["CWE-405","CWE-834"],"vendor":"pypdf","product":"pypdf","affected":["pypdf < 6.16.1"],"patched":["pypdf 6.16.1"],"published":"2026-09-01","updated":"2026-09-09","sourceUpdated":"2026-09-09T16:49:20.627","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-84310","references":[{"url":"https://github.com/py-pdf/pypdf/commit/d91ab705fd81ed1a9cec175c6958600dea1a4942","label":"security-advisories@github.com"},{"url":"https://github.com/py-pdf/pypdf/pull/3966","label":"security-advisories@github.com"},{"url":"https://github.com/py-pdf/pypdf/releases/tag/6.16.1","label":"security-advisories@github.com"},{"url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-23w6-3w8w-8484","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-23w6-3w8w-8484"},{"url":"https://github.com/py-pdf/pypdf"},{"url":"https://pypi.org/project/pypdf"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84310"}],"tags":["nvd","ghsa","pip","osv"],"epss":0.00138,"epssPercentile":0.03552,"aliases":["GHSA-23w6-3w8w-8484","PYSEC-2026-3910"],"ecosystem":"pip","ingestedAt":"2026-09-01T21:32:41.430Z","slug":"CVE-2026-84310","body":"## Overview\n\npypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consume long runtimes and large amounts of memory when retrieving document outlines with large numbers of entries or deeply nested reused paths because the traversal lacked global entry-count and nesting-depth limits. This issue is fixed in version 6.16.1.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-84310)\n\nAffected packages:\n\n- `pypdf < 6.16.1`\n\nPatched in:\n\n- `pypdf 6.16.1`\n\nSource: https://github.com/advisories/GHSA-23w6-3w8w-8484","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}