#1146638 pypdf: CVE-2026-84309

Package:
src:pypdf
Source:
src:pypdf
Submitter:
Salvatore Bonaccorso
Date:
2026-09-04 04:09:02 UTC
Severity:
normal
Tags:
#1146638#5
Date:
2026-09-04 04:07:25 UTC
From:
To:
Hi,

The following vulnerability was published for pypdf.

CVE-2026-84309[0]:
| pypdf is a free and open-source pure-python PDF library. Prior to
| 6.16.0, an attacker can craft a PDF whose cyclic tree structure
| causes pypdf/generic/_data_structures.py TreeObject.insert_child to
| follow /Next links indefinitely when a writing code path inserts a
| child, producing an infinite loop. This issue is fixed in version
| 6.16.0.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-84309
https://www.cve.org/CVERecord?id=CVE-2026-84309
[1] https://github.com/py-pdf/pypdf/security/advisories/GHSA-jp53-mhqp-8xcg
[2] https://github.com/py-pdf/pypdf/pull/3964
[3] https://github.com/py-pdf/pypdf/commit/c9ba557d565d57c53a0b3a0be06c0a4c29b0559b

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore