{"id":"CVE-2026-84309","aliases":["GHSA-jp53-mhqp-8xcg"],"url":"https://o3.security/vulnerability/CVE-2026-84309","summary":"pypdf: Possible infinite loop for TreeObject.insert_child","details":"pypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cyclic tree structure causes pypdf/generic/_data_structures.py TreeObject.insert_child to follow /Next links indefinitely when a writing code path inserts a child, producing an infinite loop. This issue is fixed in version 6.16.0.","published":"2026-09-01T19:58:46.266Z","modified":"2026-09-03T03:48:19.071847682Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"pypdf","fixedVersion":"6.16.0"}],"fix":{"url":"https://github.com/py-pdf/pypdf/commit/c9ba557d565d57c53a0b3a0be06c0a4c29b0559b","label":"py-pdf/pypdf@c9ba557"},"references":[{"type":"WEB","url":"https://github.com/py-pdf/pypdf/releases/tag/6.16.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84309.json"},{"type":"ADVISORY","url":"https://github.com/py-pdf/pypdf/security/advisories/GHSA-jp53-mhqp-8xcg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84309"},{"type":"FIX","url":"https://github.com/py-pdf/pypdf/commit/c9ba557d565d57c53a0b3a0be06c0a4c29b0559b"},{"type":"FIX","url":"https://github.com/py-pdf/pypdf/pull/3964"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-03T03:48:19.071847682Z"}}