Skip to content

chore(deps): update dependency pypdf to v6.6.2 [security]#1881

Merged
bourgeoisor merged 1 commit intoGoogleCloudPlatform:mainfrom
renovate-bot:renovate/pypi-pypdf-vulnerability
Feb 3, 2026
Merged

chore(deps): update dependency pypdf to v6.6.2 [security]#1881
bourgeoisor merged 1 commit intoGoogleCloudPlatform:mainfrom
renovate-bot:renovate/pypi-pypdf-vulnerability

Conversation

@renovate-bot
Copy link
Contributor

This PR contains the following updates:

Package Change Age Confidence
pypdf (changelog) ==6.6.0==6.6.2 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.

GitHub Vulnerability Alerts

CVE-2026-24688

Impact

An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires accessing the outlines/bookmarks.

Patches

This has been fixed in pypdf 6.6.2.

Workarounds

If projects cannot upgrade yet, consider applying the changes from PR #​3610.


Release Notes

py-pdf/pypdf (pypdf)

v6.6.2

Compare Source

Security (SEC)
  • Detect cyclic references when retrieving outlines (#​3610)

Full Changelog

v6.6.1

Compare Source

Robustness (ROB)
  • /AcroForm might be NullObject (#​3601)
  • Handle missing font bounding boxes gracefully (#​3600)

Full Changelog


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate-bot renovate-bot requested review from a team and yoshi-approver as code owners January 27, 2026 00:05
@forking-renovate forking-renovate bot added lang: python Issues specific to Python. type:security labels Jan 27, 2026
@bourgeoisor bourgeoisor merged commit 05cf27f into GoogleCloudPlatform:main Feb 3, 2026
8 checks passed
@renovate-bot renovate-bot deleted the renovate/pypi-pypdf-vulnerability branch February 9, 2026 06:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lang: python Issues specific to Python. type:security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants