CVE-2026-33929Disclosure(apache / pdfbox)

LOWCVSS 4.3 · MEDIUM

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch apache pdfbox systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache PDFBox Examples. This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.36, from 3.0.0 through 3.0.7. Users are recommended to update to version 2.0.37 or 3.0.8 once available. Until then, they should apply the fix provided in GitHub PR 427. The ExtractEmbeddedFiles example contained a path traversal vulnerability (CWE-22) mentioned in CVE-2026-23907. However the change in the releases 2.0.36 and 3.0.7 is flawed because it doesn't consider the file path separator. Because of that, a user having writing rights on /home/ABC could be victim to a malicious PDF resulting in a write attempt to any path starting with /home/ABC, e.g. "/home/ABCDEF". Users who have copied this example into their production code should apply the mentioned change. The example has been changed accordingly and is available in the project repository.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pdfbox

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
pdfbox

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-14: 2PoC Mentioned / Linked · 2026-04-14: 1Patch / Workaround · 2026-04-14: 1Technical Details · 2026-04-14: 104-14
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-33929: Apache PDFBox Examples: Path Traversal in PDFBox ExtractEmbeddedFiles Example Code https://www.openwall.com/lists/oss-security/2026/04/14/4 CVE-2026-23907 fix is flawed. A user having writing rights on /home/ABC could be victim to a malicious PDF resulting in a write attempt e.g. to /home/ABCDEF.

    Post summary

    The post announces a path traversal flaw in Apache PDFBox’s example code (CVE‑2026‑33929) and notes a flawed fix for CVE‑2026‑23907, indicating how a malicious PDF could write to arbitrary paths such as /home/ABCDEF.

    00120505
    4.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-33929 CVE-2026-33929 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33929

    Post summary

    The text lists a CVE identifier and a link without providing any additional context or details.

    0000032
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachepdfbox---

Explore more