Source: pypdf
Version: 6.9.2-2
Severity: important
Tags: security upstream
Forwarded: https://github.com/py-pdf/pypdf/pull/3964
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for pypdf.

CVE-2026-84309[0]:
| pypdf is a free and open-source pure-python PDF library. Prior to
| 6.16.0, an attacker can craft a PDF whose cyclic tree structure
| causes pypdf/generic/_data_structures.py TreeObject.insert_child to
| follow /Next links indefinitely when a writing code path inserts a
| child, producing an infinite loop. This issue is fixed in version
| 6.16.0.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-84309
    https://www.cve.org/CVERecord?id=CVE-2026-84309
[1] https://github.com/py-pdf/pypdf/security/advisories/GHSA-jp53-mhqp-8xcg
[2] https://github.com/py-pdf/pypdf/pull/3964
[3] 
https://github.com/py-pdf/pypdf/commit/c9ba557d565d57c53a0b3a0be06c0a4c29b0559b

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to