CVE-2026-24688: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-24688 is an infinite loop (Denial of Service) vulnerability in pypdf, a free and open-source pure-Python PDF library. An attacker can craft a malicious PDF file with cyclic references in its outline/bookmark structure that, when processed by pypdf, causes the application to enter an infinite loop. All pypdf versions prior to 6.6.2 are affected. The vulnerability was reported by JoakimBulow, disclosed and patched on January 26, 2026, and has a CVSS v3.1 base score of 4.3 (Medium) and a CVSS v4.0 base score of 5.1 (Medium) (Github Advisory, pypdf Advisory).

Technical details

The root cause is classified as CWE-835 (Loop with Unreachable Exit Condition / Infinite Loop). The _get_outline() method in pypdf/_doc_common.py traversed the PDF outline/bookmark linked-list structure without tracking previously visited nodes, allowing a specially crafted PDF with cyclic /Next or /First references in its outline dictionary to cause the traversal loop to never terminate. Exploitation requires that the application accesses the outline or bookmarks property of a PdfReader object on the malicious PDF. The fix, introduced in PR #3610, adds a visited set to track node object IDs and breaks the loop with a warning upon detecting a cycle (pypdf PR #3610, Fix Commit).

Impact

Successful exploitation causes a Denial of Service (DoS) by hanging the affected Python process indefinitely, exhausting CPU resources and rendering the application unresponsive. There is no impact on confidentiality or data integrity — the vulnerability is limited to availability. Systems that automatically process untrusted PDF documents (e.g., document management platforms, PDF conversion services, or data pipelines using pypdf) are most at risk of service disruption (Github Advisory).

Exploitability

A proof-of-concept exploit and a sample malicious PDF (circular_outline.pdf) are publicly available on GitHub (PoC Repository). There is no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.014% (3rd percentile), indicating a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was reported by JoakimBulow and credited in the official advisory (Github Advisory).

Exploitation steps

  1. Craft a malicious PDF: Create a PDF file with a circular outline/bookmark structure where outline dictionary entries reference each other cyclically via /Next or /First keys (e.g., Bookmark A's /Next points to Bookmark B, and Bookmark B's /Next points back to Bookmark A). A sample file (circular_outline.pdf) is available in the public PoC repository.
  2. Deliver the PDF to the target: Distribute the crafted PDF to a system or user that processes it with a vulnerable version of pypdf (< 6.6.2). This could be via email attachment, file upload to a web service, or any other delivery mechanism.
  3. Trigger outline access: Ensure the application accesses the reader.outline or reader.bookmarks property on the loaded PDF. Many document processing pipelines do this automatically for indexing or rendering purposes.
  4. Achieve DoS: The _get_outline() method enters an infinite loop traversing the cyclic references, consuming 100% of a CPU core and hanging the process indefinitely, causing a denial of service (pypdf PR #3610, PoC Repository).

Indicators of compromise

  • Process: Python process consuming 100% CPU indefinitely while processing a PDF file; process appears hung and unresponsive with no progress.
  • Logs: Application logs showing a stalled or non-completing PDF processing job; in patched versions (6.6.2+), log warnings such as "Detected cycle in outline structure for {...}" indicate a malicious or malformed PDF was submitted.
  • File System: Presence of unexpected PDF files with circular bookmark structures submitted to upload directories or processing queues.
  • Network: Unusual or repeated submission of the same PDF file to a document processing endpoint, potentially indicating probing for vulnerable services.

Mitigation and workarounds

The primary remediation is to upgrade pypdf to version 6.6.2 or later, which includes the fix for cyclic outline detection (pypdf Release 6.6.2). For projects that cannot upgrade immediately, the changes from PR #3610 can be applied manually to pypdf/_doc_common.py (pypdf PR #3610). As an additional operational control, restrict or sandbox the processing of untrusted PDF documents, and consider disabling outline/bookmark access if not required by the application. IBM has also issued a patch for affected watsonx Orchestrate with watsonx Assistant Cartridge products (IBM Advisory).

Community reactions

The vulnerability was covered by several security blogs and community sites shortly after disclosure, including write-ups titled "Ouroboros in the Outline: Infinite Loops in pypdf" on dev.to and infinitsec.net. Oracle included this CVE in its April 2026 security bulletin, and IBM issued a security bulletin for affected watsonx products in May 2026. Community reaction has been low-key given the moderate severity and limited impact scope, with no significant controversy or widespread concern noted (Oracle Advisory, IBM Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

pypdf2

Affected

sid

pypdf: 6.9.0-1

Fixed

trixie

pypdf

Affected

Ubuntu

Unknown

bionic (esm-apps)

pypdf2

Unknown

devel

pypdf

Unknown

focal (esm-apps)

pypdf2

Unknown

jammy

pypdf2

Unknown

jammy (esm-apps)

pypdf2

Unknown

noble

pypdf

Unknown

noble (esm-apps)

pypdf

Unknown

resolute

pypdf

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management