CVE-2026-23907
published 2026-03-10CVE-2026-23907: This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6. The ExtractEmbeddedFiles example…
PriorityP433medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.89%
55.2th percentile
This issue affects the
ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6.
The ExtractEmbeddedFiles example contains a path traversal vulnerability (CWE-22) because
the filename that is obtained from
PDComplexFileSpecification.getFilename() is appended to the extraction path.
Users who have copied this example into their production code should
review it to ensure that the extraction path is acceptable. The example
has been changed accordingly, now the initial path and the extraction
paths are converted into canonical paths and it is verified that
extraction path contains the initial path. The documentation has also
been adjusted.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | pdfbox | >= 2.0.24 < 2.0.37 | 2.0.37 |
| apache | pdfbox | 2.0.24 – 2.0.35 | — |
| apache | pdfbox | >= 3.0.0 < 3.0.8 | 3.0.8 |
| apache | pdfbox | 3.0.0 – 3.0.7 | — |
| apache_software_foundation | apache_pdfbox_examples | 2.0.24 – 2.0.36 | — |
| apache_software_foundation | apache_pdfbox_examples | 3.0.0 – 3.0.7 | — |
| debian | libpdfbox-java | — | — |
| debian | libpdfbox2-java | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
ghsa5.3MEDIUM
osv5.3MEDIUM
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
org.apache.pdfbox:pdfbox-examples: Apache PDFBox Example: Path Traversal via specially crafted filenames allows arbitrary file write
vendor_redhat·2026-03-10·CVSS 5.3
CVE-2026-23907 [MEDIUM] CWE-22 org.apache.pdfbox:pdfbox-examples: Apache PDFBox Example: Path Traversal via specially crafted filenames allows arbitrary file write
org.apache.pdfbox:pdfbox-examples: Apache PDFBox Example: Path Traversal via specially crafted filenames allows arbitrary file write
This issue affects the
ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6.
The ExtractEmbeddedFiles example contains a path traversal vulnerability (CWE-22) because
the filename that is obtained from
PDComplexFileSpecification.getFilename() is appended to the extraction path.
Users who have copied this example into their production code should
review it to ensure that the extraction path is acceptable. The example
has been changed accordingly, now the initial path and the extraction
paths are converted into canonical paths and it is verified that
extraction path contains the initial path. The documentation has
Debian
CVE-2026-23907: libpdfbox-java - This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0....
vendor_debian·2026·CVSS 5.3
CVE-2026-23907 [MEDIUM] CVE-2026-23907: libpdfbox-java - This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0....
This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6. The ExtractEmbeddedFiles example contains a path traversal vulnerability (CWE-22) because the filename that is obtained from PDComplexFileSpecification.getFilename() is appended to the extraction path. Users who have copied this example into their production code should review it to ensure that the extraction path is acceptable. The example has been changed accordingly, now the initial path and the extraction paths are converted into canonical paths and it is verified that extraction path contains the initial path. The documentation has also been adjusted.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
VulDB
Apache PDFBox up to 2.0.36/3.0.7 Example PDComplexFileSpecification.getFilename path traversal (Nessus ID 301969 / WID-SEC-2026-1687)
vuldb·2026-05-28·CVSS 5.3
CVE-2026-23907 [MEDIUM] Apache PDFBox up to 2.0.36/3.0.7 Example PDComplexFileSpecification.getFilename path traversal (Nessus ID 301969 / WID-SEC-2026-1687)
A vulnerability labeled as critical has been found in Apache PDFBox up to 2.0.36/3.0.7. This affects the function PDComplexFileSpecification.getFilename of the component Example. Such manipulation leads to path traversal.
This vulnerability is referenced as CVE-2026-23907. It is possible to launch the attack remotely. No exploit is available.
GHSA
Apache PDFBox Examples: Path Traversal in PDFBox ExtractEmbeddedFiles Example Code
ghsa·2026-04-14·CVSS 5.3
CVE-2026-33929 [MEDIUM] CWE-22 Apache PDFBox Examples: Path Traversal in PDFBox ExtractEmbeddedFiles Example Code
Apache PDFBox Examples: Path Traversal in PDFBox ExtractEmbeddedFiles Example Code
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache PDFBox Examples.
This issue affects the
ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.36, from 3.0.0 through 3.0.7.
Users are recommended to update to version 2.0.37 or 3.0.8 once available. Until then, they should apply the fix provided in GitHub PR 427.
The ExtractEmbeddedFiles example contained a path traversal vulnerability (CWE-22) mentioned in CVE-2026-23907. However the change in the releases 2.0.36 and 3.0.7 is flawed because it doesn't consider the file path separator. Because of that, a user having writing rights on /home/ABC could be victim to a malicious PDF resulti
OSV
CVE-2026-23907: This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2
osv·2026-03-10·CVSS 5.3
CVE-2026-23907 [MEDIUM] CVE-2026-23907: This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2
This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6. The ExtractEmbeddedFiles example contains a path traversal vulnerability (CWE-22) because the filename that is obtained from PDComplexFileSpecification.getFilename() is appended to the extraction path. Users who have copied this example into their production code should review it to ensure that the extraction path is acceptable. The example has been changed accordingly, now the initial path and the extraction paths are converted into canonical paths and it is verified that extraction path contains the initial path. The documentation has also been adjusted.
GHSA
Apache PDFBox has Path Traversal through PDComplexFileSpecification.getFilename() function
ghsa·2026-03-10
CVE-2026-23907 [MEDIUM] CWE-22 Apache PDFBox has Path Traversal through PDComplexFileSpecification.getFilename() function
Apache PDFBox has Path Traversal through PDComplexFileSpecification.getFilename() function
This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6.
The ExtractEmbeddedFiles example contains a path traversal vulnerability (CWE-22) because the filename that is obtained from PDComplexFileSpecification.getFilename() is appended to the extraction path.
Users who have copied this example into their production code should review it to ensure that the extraction path is acceptable. The example has been changed accordingly, now the initial path and the extraction paths are converted into canonical paths and it is verified that extraction path contains the initial path. The documentation has also been adjusted.
OSV
Apache PDFBox has Path Traversal through PDComplexFileSpecification.getFilename() function
osv·2026-03-10
CVE-2026-23907 [MEDIUM] Apache PDFBox has Path Traversal through PDComplexFileSpecification.getFilename() function
Apache PDFBox has Path Traversal through PDComplexFileSpecification.getFilename() function
This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6.
The ExtractEmbeddedFiles example contains a path traversal vulnerability (CWE-22) because the filename that is obtained from PDComplexFileSpecification.getFilename() is appended to the extraction path.
Users who have copied this example into their production code should review it to ensure that the extraction path is acceptable. The example has been changed accordingly, now the initial path and the extraction paths are converted into canonical paths and it is verified that extraction path contains the initial path. The documentation has also been adjusted.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-23907 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-23907 [MEDIUM] CVE-2026-23907 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23907 :
Java vulnerability analysis and mitigation
This issue affects the
ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6.
The ExtractEmbeddedFiles example contains a path traversal vulnerability (CWE-22) because
the filename that is obtained from
PDComplexFileSpecification.getFilename() is appended to the extraction path.
Users who have copied this example into their production code should
review it to ensure that the extraction path is acceptable. The example
has been changed accordingly, now the initial path and the extraction
paths are converted into canonical paths and it is verified that
extraction path contains the initial path. The documentation has also
been adjusted.
Source : NVD
## 5.3
Score
Published Marc
Bugzilla
CVE-2026-33929 Apache PDFBox: Apache PDFBox: Arbitrary file write via path traversal in ExtractEmbeddedFiles example
bugzilla·2026-04-14·CVSS 5.3
CVE-2026-33929 [MEDIUM] CVE-2026-33929 Apache PDFBox: Apache PDFBox: Arbitrary file write via path traversal in ExtractEmbeddedFiles example
CVE-2026-33929 Apache PDFBox: Apache PDFBox: Arbitrary file write via path traversal in ExtractEmbeddedFiles example
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache PDFBox Examples.
This issue affects the
ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.36, from 3.0.0 through 3.0.7.
Users are recommended to update to version 2.0.37 or 3.0.8 once
available. Until then, they should apply the fix provided in GitHub PR
427.
The ExtractEmbeddedFiles example contained a path traversal vulnerability (CWE-22) mentioned in CVE-2026-23907. However the change in the releases 2.0.36 and 3.0.7 is flawed because it doesn't consider the file path separator. Because of that, a user having writing rights on /home/ABC could be
2026-03-10
Published