pypdf (a pure-Python PDF library) contains an infinite loop condition in versions prior to 6.6.2 that can be triggered by a crafted PDF when the library processes PDF outlines/bookmarks. When an application accesses or parses the document’s outlines/bookmarks, malformed outline structures can cause non-terminating processing, resulting in a hang. The issue is fixed in pypdf 6.6.2.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a small standalone proof-of-concept for CVE-2026-24688 affecting pypdf outline parsing. It is not part of a known exploit framework. The repo contains three executable/support files plus a README: (1) create_malicious_pdf.py generates crafted PDFs with circular bookmark/outline object graphs, including a direct /Next loop and a nested /First-based cycle; (2) simple_read_pdf.py is a reproducer that opens a PDF with PdfReader and explicitly accesses reader.outline, the vulnerable sink; (3) test_pypdf.sh automates installation of pypdf 6.6.0 and runs an inline Python snippet that opens ./malicious_circular_outline.pdf and accesses outline, intentionally causing the hang/resource exhaustion. The exploit capability is denial of service only: no code execution, persistence, or data theft. The main attack vector is file-based delivery of a malicious PDF to any local application or workflow that uses vulnerable pypdf and reads outline/bookmark structures. Fingerprintable artifacts are primarily local file paths and upstream GitHub references; there are no hardcoded C2 servers, IPs, or network callbacks. Overall, this is a credible PoC exploit repository demonstrating resource-exhaustion/system-crash behavior through malformed PDF structure.
Repository purpose: proof-of-concept for CVE-2026-24688 in the Python library pypdf, demonstrating a denial-of-service condition caused by circular references in PDF outline/bookmark structures. Structure and key files: - README.md: Describes the vulnerability (outline parsing infinite loop due to missing cycle detection in pypdf/_doc_common.py::_get_outline), impact (CPU 100% + rapid memory growth), reproduction steps, and notes fix in pypdf 6.6.2. - create_malicious_pdf.py (Python): Generates malicious PDFs by manually constructing /Outlines dictionaries and outline items with circular references. Two variants: 1) create_malicious_circular_outline(): A->/Next=B and B->/Next=A (direct cycle). 2) create_nested_circular_outline(): cycle via nesting using /First and /Next (A has child B, B next C, C child A). Output files: malicious_circular_outline.pdf and malicious_nested_circular.pdf. - simple_read_pdf.py (Python): Reproducer/driver that opens a given PDF with PdfReader and explicitly accesses reader.outline (the trigger). It also prints metadata and attempts text extraction, but the exploit condition is specifically the outline access. - test_pypdf.sh (Bash): Automated unsafe reproducer that installs pypdf==6.6.0 and runs an inline Python snippet that opens ./malicious_circular_outline.pdf and accesses reader.outline, intentionally causing the hang/resource exhaustion. Exploit capabilities: - Generates a crafted PDF payload that, when parsed by vulnerable pypdf and when outline/bookmarks are accessed, causes an infinite loop and repeated allocations. - Results in a system-impacting DoS (resource exhaustion). No code execution, no network C2, and no persistence mechanisms are present. Network/endpoint behavior: - No network communication in the exploit code. Observable endpoints are limited to local file paths (malicious PDFs) and documentation links to upstream GitHub/advisory.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.