Path Traversal Vulnerability in Apache PDFBox Affects Multiple Versions
CVE-2026-23907
5.3MEDIUM
What is CVE-2026-23907?
A path traversal vulnerability exists in the ExtractEmbeddedFiles example of Apache PDFBox, impacting versions from 2.0.24 to 3.0.7. This flaw arises because the filename obtained through the file extraction process can be manipulated to access unauthorized paths within the server. Developers are advised to review and validate the extraction paths in their implementations since improper handling can lead to potential data exposure or unauthorized access. Recent updates have improved security by ensuring that extraction paths are correctly validated against the initial paths, thus protecting against exploitation.
Affected Version(s)
Apache PDFBox Examples 2.0.24 <= 2.0.35
Apache PDFBox Examples 3.0.0 <= 3.0.6