CVE-2026-84309Medium▾ Sunlitpypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cyclic tree structure causes pypdf/generic/_data_structures.py TreeObject.insert_child to follow /Next links indefinitely when a …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 2.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.1%
Last analysed / modified upstream
pypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cyclic tree structure causes pypdf/generic/_data_structures.py TreeObject.insert_child to follow /Next links indefinitely when a writing code path inserts a child, producing an infinite loop. This issue is fixed in version 6.16.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
pypdf < 6.16.0Patched in:
pypdf 6.16.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-82398Mediumpypdf is a free and open-source pure-python PDF library
CVE-2026-84311Mediumpypdf is a free and open-source pure-python PDF library
CVE-2026-84310Mediumpypdf is a free and open-source pure-python PDF library
CVE-2026-59936Highpypdf: Possible infinite loop for not terminated inline images
CVE-2026-59935Highpypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
CVE-2026-54530Mediumpypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction