CVE-2026-84310

ADVISORY - github

Summary

Impact

An attacker who uses this vulnerability can craft a PDF which leads to long runtimes and large memory consumption. This requires accessing the outlines of a document with either lots of entries or nested outlines with long re-used nesting paths.

Patches

This has been fixed in pypdf==6.16.1.

Workarounds

If you cannot upgrade yet, consider applying the changes from PR #3966.

Common Weakness Enumeration (CWE)

ADVISORY - nist

Asymmetric Resource Consumption (Amplification)

Excessive Iteration

ADVISORY - github

Asymmetric Resource Consumption (Amplification)

Excessive Iteration

ADVISORY - redhat

Allocation of Resources Without Limits or Throttling


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in