CVE-2026-84311: Pypdf Project Pypdf
Low severity, CVSS 3.3. EPSS: 0.1% chance of exploitation in the next 30 days.
pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_page.py PageObject._extract_text and PageObject.extract_xform_text to traverse a directed acyclic graph of reused form XObjects in which each form invokes a child multiple times, creating exponentially many traversal paths and causing long runtimes and large memory consumption. This issue is fixed in version 6.16.1.
Affected products
- Pypdf Project Pypdf: before 6.16.1 (fixed in 6.16.1)
Published 2026-09-01. Last modified 2026-10-05.