Loading market data...
← Back to CVE feed

CVE-2026-84311

UNKNOWN View on NVD ↗

Description

pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_page.py PageObject._extract_text and PageObject.extract_xform_text to traverse a directed acyclic graph of reused form XObjects in which each form invokes a child multiple times, creating exponentially many traversal paths and causing long runtimes and large memory consumption. This issue is fixed in version 6.16.1.

Published: Sep 01, 2026 21:18 UTC Modified: Sep 02, 2026 16:17 UTC