Pypi · Pypdf · CVE-2026-24688
**Name of the Vulnerable Software and Affected Versions**
pypdf versions prior to 6.6.2
**Description**
A flaw exists in the `pypdf` library that allows attackers to trigger an infinite loop by creating a PDF file with cyclic outline references. This requires accessing the outlines or bookmarks within the PDF.
**Recommendations**
Upgrade to pypdf version 6.6.2 or later.
If upgrading is not immediately possible, apply the changes from Pull Request #3610.