Summary
pypdf: Possible long runtimes/large memory usage when retrieving outlines
Advisory details
Impact
An attacker who uses this vulnerability can craft a PDF which leads to long runtimes and large memory consumption. This requires accessing the outlines of a document with either lots of entries or nested outlines with long re-used nesting paths.
Patches
This has been fixed in pypdf==6.16.1.
Workarounds
If you cannot upgrade yet, consider applying the changes from PR #3966.
References
Related vulnerabilities
All Supply chain →- MEDIUMCVE-2026-84311
pypdf: Possible long runtimes/large memory usage when extracting XForm objects
- MEDIUMCVE-2026-45822
decode-uri-component: Denial of service via exponential decoding of malformed percent-encoded input
- MEDIUMCVE-2026-71852
pypdf: Possible long runtimes/large memory usage for large CID font width ranges
- MEDIUMGHSA-mj63-m3rc-8ppr
league/commonmark: Denial of service via deeply nested XML output
- HIGHCVE-2026-64641
Next.js: Denial of Service in App Router using Server Actions
- HIGHGHSA-7q9c-hpx7-9cwm
TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop