
CVE-2026-33929: Apache PDFBox Examples: Path Traversal in PDFBox ExtractEmbeddedFiles Example Code https://www.openwall.com/lists/oss-security/2026/04/14/4 CVE-2026-23907 fix is flawed. A user having writing rights on /home/ABC could be victim to a malicious PDF resulting in a write attempt e.g. to /home/ABCDEF.
Post summary
The post announces a path traversal flaw in Apache PDFBox’s example code (CVE‑2026‑33929) and notes a flawed fix for CVE‑2026‑23907, indicating how a malicious PDF could write to arbitrary paths such as /home/ABCDEF.

