{"id":"DEBIAN-CVE-2026-23907","details":"This issue affects the  ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6.   The ExtractEmbeddedFiles example contains a path traversal vulnerability (CWE-22) because  the filename that is obtained from  PDComplexFileSpecification.getFilename() is appended to the extraction path.  Users who have copied this example into their production code should  review it to ensure that the extraction path is acceptable. The example  has been changed accordingly, now the initial path and the extraction  paths are converted into canonical paths and it is verified that  extraction path contains the initial path. The documentation has also  been adjusted.","modified":"2026-09-18T08:47:29.855983071Z","published":"2026-03-10T18:18:16.960Z","upstream":["CVE-2026-23907"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-23907"}],"affected":[{"package":{"name":"libpdfbox-java","ecosystem":"Debian:12","purl":"pkg:deb/debian/libpdfbox-java?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:1.8.16-2","1:1.8.16-3","1:1.8.16-4","1:1.8.16-5"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-23907.json"}},{"package":{"name":"libpdfbox-java","ecosystem":"Debian:13","purl":"pkg:deb/debian/libpdfbox-java?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:1.8.16-5"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-23907.json"}},{"package":{"name":"libpdfbox-java","ecosystem":"Debian:14","purl":"pkg:deb/debian/libpdfbox-java?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:1.8.16-5"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-23907.json"}},{"package":{"name":"libpdfbox2-java","ecosystem":"Debian:12","purl":"pkg:deb/debian/libpdfbox2-java?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.0.27-2","2.0.29-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-23907.json"}},{"package":{"name":"libpdfbox2-java","ecosystem":"Debian:13","purl":"pkg:deb/debian/libpdfbox2-java?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.0.29-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-23907.json"}},{"package":{"name":"libpdfbox2-java","ecosystem":"Debian:14","purl":"pkg:deb/debian/libpdfbox2-java?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.0.29-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-23907.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}