CVE-2026-84309
pypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cyclic tree structure causes pypdf/generic/_data_structures.py TreeObject.insert_child to follow /Next links indefinitely when a writing code path inserts a child, producing an infinite loop. This issue is fixed in version 6.16.0.
- Published Sep 1, 2026
- CVSS 6.9 medium
- 0.2% chance of exploitation in the next 30 days (EPSS)
- A fix is available