CVE-2026-23907Disclosure(apache / pdfbox-examples)

LOWCVSS 5.3 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6. The ExtractEmbeddedFiles example contains a path traversal vulnerability (CWE-22) because the filename that is obtained from PDComplexFileSpecification.getFilename() is appended to the extraction path. Users who have copied this example into their production code should review it to ensure that the extraction path is acceptable. The example has been changed accordingly, now the initial path and the extraction paths are converted into canonical paths and it is verified that extraction path contains the initial path. The documentation has also been adjusted.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pdfbox-examples

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-03-10); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
pdfbox-examples

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-10: 4Mentions · 2026-04-14: 1PoC Mentioned / Linked · 2026-04-14: 1Technical Details · 2026-03-10: 2Technical Details · 2026-04-14: 103-1004-14
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-104
Disclosure3General1
2026-04-141
Disclosure1
Full discourse5 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-23907: Apache PDFBox Examples: Path Traversal in PDFBox ExtractEmbeddedFiles Example Code https://www.openwall.com/lists/oss-security/2026/03/10/1 Users who have copied this example into their production code should review it to ensure that the extraction path is acceptable

    Post summary

    The message alerts developers to a path traversal vulnerability in Apache PDFBox's ExtractEmbeddedFiles example and urges code review.

    01041778
    4.4K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-33929: Apache PDFBox Examples: Path Traversal in PDFBox ExtractEmbeddedFiles Example Code https://www.openwall.com/lists/oss-security/2026/04/14/4 CVE-2026-23907 fix is flawed. A user having writing rights on /home/ABC could be victim to a malicious PDF resulting in a write attempt e.g. to /home/ABCDEF.

    Post summary

    The post highlights two CVEs in Apache PDFBox, detailing a path traversal flaw in example code and how a flawed fix could allow malicious PDFs to write arbitrary files.

    00120505
    4.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-23907 CVE-2026-23907 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23907 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post simply references CVE-2026-23907 and provides a link to a vulnerability details page, with no additional technical, exploit, or remediation information.

    0000041
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-23907 This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.36, from 3.0.0 through 3.0.7. The ExtractEmbeddedFiles example contai… https://www.cve.org/CVERecord?id=CVE-2026-23907 ----- Traducción: Este problema afect… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-23907, which affects the ExtractEmbeddedFiles example in Apache PDFBox across specific versions, without providing PoC, exploit code, or patch information.

    0000027
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23907 This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.36, from 3.0.0 through 3.0.7. The ExtractEmbeddedFiles example contai… https://www.cve.org/CVERecord?id=CVE-2026-23907

    Post summary

    The text reports CVE‑2026‑23907 as affecting Apache PDFBox’s ExtractEmbeddedFiles example across certain versions, but provides no evidence of exploitation, PoC, or remediation.

    00000259
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachepdfbox-examples---

Explore more