Résumé
pypdf: Possible infinite loop for TreeObject.insert_child
Détails de l’avis
Impact
An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires a (usually writing) code path where TreeObject.insert_child is involved.
Patches
This has been fixed in pypdf==6.16.0.
Workarounds
If you cannot upgrade yet, consider applying the changes from PR #3964.
Références
Vulnérabilités liées
Tout Supply chain →- HIGHCVE-2026-61556
LiquidJS has an infinite loop vulnerability in its `strip_html` filter
- HIGHCVE-2026-54623
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
- HIGHCVE-2026-63202
netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding
- HIGHCVE-2026-63124
netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary
- MEDIUMCVE-2026-71436
Mermaid XY Charts are vulnerable to an infinite loop DoS
- MEDIUMCVE-2026-68499
re2: Global `String.prototype.match` with an empty-matchable pattern never advances → infinite loop with unbounded native memory growth (DoS)