CVE Feed

    Dashboard / CVE / CVE-2026-23907

    CVE-2026-23907

    This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6. The ExtractEmbeddedFiles example contains a path traversal vulnerability (CWE-22) because the filename that is obtained from PDComplexFileSpecification.getFilename() is appended to the extraction path. Users who have copied this example into their production code should review it to ensure that the extraction path is acceptable. The example has been changed accordingly, now the initial path and the extraction paths are converted into canonical paths and it is verified that extraction path contains the initial path. The documentation has also been adjusted.

    Published:Mar 10, 2026
    Last Modified:Apr 16, 2026
    EPS:Mar 10, 2026
    EPSS Score:0.00059
    CVSS Score:5.3

    Affected Products

    Vendor
    Apache
    Product
    Pdfbox
    Vendor
    Apache
    Product
    Pdfbox Examples

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High