Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-84310

Опубликовано: 01 сент. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consume long runtimes and large amounts of memory when retrieving document outlines with large numbers of entries or deeply nested reused paths because the traversal lacked global entry-count and nesting-depth limits. This issue is fixed in version 6.16.1.

A flaw was found in pypdf. A remote attacker could craft a malicious PDF document with specially designed outlines. Processing this document would cause the pypdf library to consume excessive processing time and memory, leading to a Denial of Service (DoS) condition. This vulnerability is due to a lack of limits on entry-count and nesting-depth during outline traversal.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Out of support scope
Lightspeed Corelightspeed-core/lightspeed-stack-rhel9Fix deferred
Lightspeed Corelightspeed-core/rag-tool-cpu-rhel9Fix deferred
Lightspeed Corelightspeed-core/rag-tool-cuda-12.9-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-chatbot-rhel8Out of support scope
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-cuda-rhel9Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-gaudi-rhel9Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-rocm-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2527049pypdf: pypdf: Denial of Service via crafted PDF outlines

EPSS

Процентиль: 4%
0.00138
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

ubuntu
15 дней назад

(pypdf is a free and open-source pure-python PDF library. Prior to 6.16 ...)

nvd
15 дней назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consume long runtimes and large amounts of memory when retrieving document outlines with large numbers of entries or deeply nested reused paths because the traversal lacked global entry-count and nesting-depth limits. This issue is fixed in version 6.16.1.

debian
15 дней назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.16 ...

github
15 дней назад

pypdf: Possible long runtimes/large memory usage when retrieving outlines

CVSS3: 3.3
fstec
около 1 месяца назад

Уязвимость функции _get_outline() файла pypdf/_doc_common.py библиотеки Python для работы с PDF файлами PyPDF, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 4%
0.00138
Низкий

5.5 Medium

CVSS3