CVE-2026-23907MEDIUMCVSS 5.3≥ 2.0.24, ≤ 2.0.35·≥ 3.0.0, ≤ 3.0.62026-03-10
CVE-2026-23907 [MEDIUM] CWE-22 CVE-2026-23907: This issue affects the
ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, f
This issue affects the
ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6.
The ExtractEmbeddedFiles example contains a path traversal vulnerability (CWE-22) because
the filename that is obtained from
PDComplexFileSpecification.getFilename() is appended to the extraction path.
Users who have copied t
cvelistv5nvd