{"id":"openSUSE-SU-2026:20923-1","summary":"Security update for apache-pdfbox","details":"This update for apache-pdfbox fixes the following issues:\n\nUpdate to version 2.0.36.\n\nSecurity issues fixed:\n\n- CVE-2026-33929: path traversal in the `ExtractEmbeddedFiles` example code can lead to arbitrary file writes\n  (bsc#1262046).\n\nOther updates and bugfixes:\n\n- Version 2.0.36:\n  - XMPBox removes namespaces on serialization\n  - False negative on PDFA-1b validation : missing field type\n  - PlainText.Paragraph.getLines extremely slow on long lines\n  - Valid PDF/A 1B is rejected\n  - Potential StackOverflows in BaseParser\n  - Unknown code in Huffman RLE stream\n  - IllegalArgumentException: Can't add attribute to 0-length text\n  - TTFSubsetter.buildGlyfTable() modifies glyphIds while iterating over its entries possibly causing\n    ConcurrentModificationException to be thrown\n  - IndexOutOfBoundsException in Type1CharStringParser.processCallSubr()\n  - Exception \"No type defined for {http://www.aiim.org/pdfa/ns/id/}rev\" when trying to determine version of PDF/A-4\n    document\n  - allow new PDF/A-4 conformance levels\n  - pdfbox-app-X.X.X-sources.jar on maven central are empty (and javadoc jar is missing)\n  - Cmd line docs\n  - IllegalArgumentException: Multiplying two matrices produces illegal values in PDFStreamEngine.processAnnotation()\n  - XmpParsingException: Schema is not set in this document: http://ns.adobe.com/xap/1.0/sType/ResourceEvent#\n  - NullPointerException in FontMapperImpl.getFontMatches()\n  - border style in FDFAnnotation is not initialized if width is 0\n  - German umlauts are not rendered\n  - Invalid type in Schema not detected when in XML attributes\n  - Serializing produces date \"1-01-01T00:00:00+01:00\"\n  - Seconds of date \"D:2015-02-03T10:11:12\" returned as 0\n  - Confusing naming of \"DerivedFrom\" property getter in XMPMediaManagementSchema\n  - ClassCastException in XMPMediaManagementSchema.getHistory()\n  - IllegalArgumentException: Input buffer too short in StandardSecurityHandler.computeRC4key()\n  - IllegalArgumentException: Width (0) and height (0) cannot be \u003c= 0 when printing landscape rotated with\n    RASTERIZE_DPI_AUTO\n  - DateConverter fails on valid date\n  - ClassCastException: class org.apache.xmpbox.type.TextType cannot be cast to class\n    org.apache.xmpbox.type.ArrayProperty in DublinCoreSchema.getCreatorsProperty()\n  - tiff:YCbCrSubSampling and tiff:YCbCrPositioning have wrong cardinality\n  - ClassCastException: class org.apache.xmpbox.type.FlashType\n  - Cannot find a definition for the namespace http://www.w3.org/1999/02/22-rdf-syntax-ns#, property:\n    rdf:Description http://ns.adobe.com/xap/1.0/sType/ResourceEvent#, property:stEvt:action\n  - XmpParsingException: Missing pdfaSchema:property in type definition in lenient mode\n  - XmpParsingException: Unknown property value type : Open Choice of Integer\n  - XmpParsingException: Property 'CountryCode' not defined in http://www.epo.org/patent-bibliographic-data/1.0/\n  - date \"0-00-00T00:00:00-04:00\" read as \"0002-11-30T00:00:00-40:00\"\n  - XmpParsingException: Type 'stRef:documentName' not defined in http://ns.adobe.com/xap/1.0/sType/ResourceRef# in\n    lenient mode\n  - Invalid PDF/A namespace definition, prefix: xmlns, namespace: http://www.aiim.org/pdfa/ns/extension/\n    http://www.aiim.org/pdfa/ns/extension/, property: pdfaExtension:schemas\n  - NegativeArraySizeException in PredictorOutputStream()\n  - NullpointerException in PDAcroForm.getField(Line 485)\n  - OutOfMemoryError when trying to extract text from pdf\n  - Outlines circular reference vulnerability\n  - Rendered text missing\n  - Inverted images due to enlarged decode array\n  - PDF displays garbled characters in Adobe Reader but renders correctly in web browsers\n  - NullPointerException while merging PDFs with output intents\n  - Valid XMP Extension Schema rejected\n  - Remove dead code from PDFMarkedContentExtractor\n  - Include test file in test class\n  - Get and Add PageTextSchema\n  - Remove / deprecate TypeMapping.getAssociatedSchemaObject()\n  - Support Seq / Bag mixup in lenient mode\n  - Parse xmp files in lenient mode that have no processing instructions\n  - deprecate getPDFIdentificationSchema() in favor of getPDFAIdentificationSchema()\n  - Support TIFF-files with FillOrder=2 conversion to PDF\n  - Remove / deprecate unused parts of PDIndexed\n  - modernize rat exclusions\n- Version 2.0.35:\n  - NegativeArraySizeException with PDF file with huge fonts\n  - Inline image bug with multi-byte newline tokens\n  - fix initial ByteArrayOutputStream size for deflate operation\n  - PDF takes an hour to render\n  - Splitter does not include structure tree in documents past the first split\n  - build fails on jdk11\n  - Load a TTF font which is from Mac OS throw an exception\n  - Wrong glyphs since PDFBOX-5790\n  - ClassCastException on broken file in PDEmbeddedFilesNameTreeNode.convertCOSToPD()\n  - invalid XMP generated when Apache Xalan in the classpath\n  - XMP JobType constructor ignores fieldPrefix\n  - NullPointerException in xmpbox serializer if a date is empty\n  - Rendering issue with type 2 shading: vertical expansion\n  - Possible infinite loop in shading code\n  - Potential OOM in XrefStreamParser\n  - Potential StackOverflow in PDFStreamParser\n  - Potential StackOverflow in PDPageTree's getInheritableAttribute\n  - Potential OOM in Type1Lexer\n  - Potential OOM in PfbParser\n  - PDMarkedContentReference.setMCID() should not accept negative numbers\n  - IllegalPathStateException: missing initial moveto in path definition\n  - Fix possible ClassCastException\n  - NullPointerException in COSDictionary\n  - StringIndexOutOfBoundsException in PlainText$Paragraph.getLines()\n  - LZWFilter crashes, probably not handling the KwKwK special case\n  - NullPointerException in PDNumberTreeNode.getNumbers()\n  - UnsupportedOperationException: JPX color spaces don't support drawing\n  - Signing tries to set byteRange of old signature (2)\n  - ClassCastException in PDOptionalContentProperties.getBaseState()\n  - Add test for embedded files\n  - set size for ByteArrayOutputStreams\n  - avoid creation of temporary objects when parsing hex values\n  - avoid unnecessary map lokups\n  - remove unnecessary iteration and StringBuilder creation\n  - Support reverse landscape orientation for printing\n  - Add test coverage for orphan annotation\n  - Remove orphan popup parent annotation\n  - Improve XmpSerializer test by verifying its output\n  - Consider rotation of page when applying overlay\n  - Preserve Perms dictionary when signing\n  - Check /ParentTree against /K tree\n  - Add test for 5521\n  - Refactor RC4Cipher\n  - Regression tests for 2.0.35\n- Version 2.0.34:\n  - PageDrawer is not rendering unrotatable Annotations on rotated pages\n  - Zero-width non-joiner characters visible in generated PDF\n  - Surrogate pairs with combining diacritics are incorrectly ordered on text extraction\n  - TestCreateSignature.testCreateSignedTimeStamp checkLTV build test fail (2) / Support several issuers\n  - IllegalArgumentException: Width (0) and height (0) must be non-zero\n  - Merge docs with specific characteristics causes stack overflow - InvalidKeyException: Supplied key\n   (sun.security.ec.ECPrivateKeyImpl) is not a RSAPrivateKey\n  - Can't read the embedded Type1 font: Found Token[kind=NAME,text=def] but expected begin\n  - Wrong size entry in trailer after incremental save\n  - FileSystemFontProvider doesn't register failed type1 fonts\n  - Text annotation crosshair symbol too small when using Adobe symbol font\n  - Orphan /OpenAction destination page kept in merge\n  - PDFRenderer causes endless loop\n  - Invalid stream length: 0, stream start position: \u003cxxx\u003e\n  - Inline image incorrectly parsed (2)\n  - IllegalArgumentException: Not a valid Unicode code point: 0xE28496\n  - Type 3 font glyphs not displayed\n  - Rendered PDF is missing shading pattern graphics\n  - NPE during merge\n  - Class cast exception in building PDDestinationNameTreeNode\n  - DomXmpParser incorrectly expects namespaces on attribute level\n  - BDC processor mishandles property name\n  - Can't render some Type1C fonts.\n  - PDF to Image conversion results in a blank white page\n  - Implement PDFormXObject.setGroup()\n  - CertificateVerifier.isSelfSigned() should not throw an exception\n  - Use Zapf Dingbats code for cross text annotation\n  - Support PushPin, Tag and Graph file attachment annotation icons\n  - Improve PDFMergerUtility memory footprint\n  - Support rare RC4 encryption where R=4, key length \u003c 128 bits\n  - Improve checkWithNumberTree() test\n  - Use SHA256 instead of MD5 for document id\n- Version 2.0.33:\n  - Character positions shifted\n  - Incorrectly extracted text (broken words)\n  - Wrong color of uncolored tiling pattern\n  - OutOfMemoryError - during renderImageWithDPI\n  - BaseParser fails when a number is followed by a string starting with 'e'\n  - Type3 font is not rendered\n  - Flattening removes all annotations when widget annotation has no page\n  - Image lost on page render\n  - extra whitespaces when extracting Arabic text\n  - SMaskInData not supported for JPX images\n  - Kid Widget /DA is ignored in setDefaultAppearance() call\n  - Radio button can't be set\n  - the PDDocument.documentId does not seem to be written into the flat byteStream\n  - PDFBox is unable to remove ID\n  - Fix last step of the build process\n  - StringIndexOutOfBoundsException in AppearanceGeneratorHelper\n  - ClassCastException in SetLineJoinStyle.process()\n  - Unable to load password protected pdf\n  - PDFBox not extracting text of non-latin languages(tamil, bengali) properly but adobe reader's save as text does\n  - Checkstyle\n  - [PATCH] Detect CMYK image without relying on metadata\n  - Regression from PDFBOX-5841: Text extraction with rotation magic fails for PDF with multiple content streams in a\n    page\n  - PDF render blank page: The end of the stream doesn't point to the correct offset, using workaround to read the\n    stream, stream start position: 196, length: 0, expected end position: 196\n  - CVE for Lucene libraries\n  - The pattern created with PDFBox shows inconsistent colors between Safari and Adobe.\n  - BDC sequence with resource reference instead of with MCID\n  - StackOverflowError in PDFieldFactory.findFieldType\n  - ClassCastException in AnnotationValidator\n  - The CPU usage of a PDF file with a size of 85.6 MB is abnormal\n  - Many ZapfDingbats symbols do not appear when page is rendered.\n  - IOException when reading isolated \"+\"\n  - IllegalArgumentException: capacity \u003c 0: (-75475220 \u003c 0) in RandomAccessReadBuffer constructor\n  - FontBox spawns a `cmd` subprocess to read an environment variable (on Windows)\n  - Implement PDF 2.0 dash phase clarification (2)\n  - Particular PDF fails on renderImageWithDPI call\n  - PDType0Font return invalid space width\n  - Icons of text annotations sometimes too large\n  - Orphan page check doesn't check annotation destinations\n  - NPE in COSArray.indexOfObject\n  - NPE in PagePane.mouseMoved()\n  - ArrayIndexOutOfBoundsException in CMap.toInt()\n  - Show ASN.1 decoded Contents for Signature-Dictionary\n  - Exchange hard-coded values for variables and provide command-line options in TextToPDF component\n  - Long rendering time of fonts in a specific PDF\n  - Support imageio-jnr / imageio-openjpeg library for JPEG2000 decoding\n  - Improve ExtractTTFFonts\n  - Change Loglevel from Warn to info when rebuilding font cache\n  - Support OCG visibility expressions\n  - Add page getter/setter to PDObjectReference\n  - Support long values for COSInteger objects\n  - Empty constructor for PDViewerPreferences\n  - Add check of /P to PDFMergerUtilityTest\n  - support Markdown extraction from the command line\n  - Calculate dpi dynamically when printing with raster\n  - Remove orphan annotations in structure tree\n  - Add font name to PrintTextLocations\n  - Improve detection whether printing or viewing\n  - Hi CPU and memory usage when converting a PDF with type 4 shading\n  - 2.0 builds fail on jenkins because jdk11 no longer supported\n- Version 2.0.32:\n  - preflight-app fails on Java 11+ with NoClassDefFoundError: javax/activation/DataSource\n  - AppearanceGeneratorHelper assumes fontscale 1000\n  - Remove release subproject\n  - Don't use a predefined CMap if a ToUnicode CMap is present\n  - Regression NPE in Splitter\n  - The content of the specified font is lost, Google Chrome can display it\n  - Crash for Softmask with incorrect backdrop color components\n  - Observable Timing Discrepancy (Timing Attack)\n  - Black rectangle over image\n  - Wrong font substitution for Wingdings\n  - PDDocument#importPage slowed down by factor 1300\n  - Split aborts with broken destinations\n  - IllegalArgumentException: Parameter must be 1-based, but is 0 when using PDFTextStripperByArea\n  - Files created with PDFMergerExample are not correct PDF/A\n  - Missing /Subtype and /Type in Metadata not detected\n  - Multiple exceptions coming from org.apache.fontbox.ttf for different PDFs\n  - IOException: Error expected floating point numberactual='-12.-1'\n  - NullPointerException: Cannot invoke \"String.codePointAt(int)\" because \"uni\" is null\n  - DomXmpParser - IllegalArgumentException: prefix cannot be \"null\" when creating a QName\n  - ClassCastException: org.apache.pdfbox.cos.COSNull cannot be cast to org.apache.pdfbox.cos.COSDictionary\n  - IllegalArgumentException: Width (26) and height (0) must be non-zero\n  - There is an exception when getting embedded font, is it compatible?\n  - Infinite loop after splitting and saving PDF / giant result files\n  - JPEGFactory. Reduce logging severity when no image metadata is present\n  - Add test for surrogate pair character ð© ̧1⁄2\n  - Update unicode Scripts.txt\n  - Include a PDFA check with VeraPDF for CreatePDFATest\n  - Add center constructor parameter to PDFPageable and to pdfbox-app\n  - When splitting, keep named page destinations that are part of target document(s)\n  - When this PDF is rendered with the \"f\" Operator, a black screen appears.\n  - Investigate why we get \"response contains wrong nonce value\" during build tests\n- Version 2.0.31:\n  - [PATCH] Split pdf lose accessibility tags\n  - Allow creating of PDFXObjectImage without accessing to the image stream\n  - PfbParser fails to parse PFB font with multiple binary records.\n  - Lines vanish when printing on MacOS\n  - java.lang.IllegalArgumentException: Provided dictionary is not of type 'COSName{OCG}'\n  - The embedded font DroidSansFallbackFull reports an error when parsing, and finally uses lastResortFont, resulting in\n    garbled fonts.\n  - COSName caches already cached hashCode\n  - Font operation takes a long time with 3.0.1\n  - NullPointerException in TTFSubsetter.buildPostTable()\n  - Problem converting PDF to image (java.awt.color.CMMException: Can not access specified profile)\n  - Set the default value for PDNonTerminalField\n  - java.lang.ArrayIndexOutOfBoundsException Bug Report\n  - Wrong colors in PDF since PDFBOX-5488\n  - Java 7 support on 2.0\n  - Convert to image exception\n  - PDF conversion in this format is very slow. Is there any room for optimization?\n  - IllegalArgumentException: -Infinity is not a finite number\n  - Inconsistent signature page handling when signing in existing  signature fields\n  - Add leading \"0\" for octal values in MacOSRomanEncoding\n  - DataFormatException: invalid distance too far back\n  - Grayscale JPEG rendered multicolor\n  - OutOfMemoryError in FileSystemFontsProvider.scanFonts\n  - NPE in PageDrawer.getPaint()\n  - Issue with embedded Font and descendant Font\n  - LCMS error 13: Mismatched alpha channels\n  - Enable Native Markdown Extraction in Apache PDFBox\n  - When splitting, keep page destinations that are part of target document(s)\n  - Replace Exception with some repair attempt\n- Version 2.0.30:\n  - Regression unicode mapping in Korean document\n  - Operators \"q\" and \"Q\" should also preserve text matrices\n  - Signature Image not Rendered starting with PDFBox 2.0.23\n  - Fonts are not subsetted when saving incrementally\n  - Bug in PDFMergerUtility#mergeFields\n  - Password protected PDF opens in GUI apps but PDFbox says invalid password\n  - Wrong error message \"2.4.1 : Invalid Color space, The operator \"rg\" can't be used with CMYK Profile\"\n  - Make FDF annotations more compliant with the specification\n  - NPE in DomXmpParser.parseLiDescription\n  - Regression: NoSuchElementException in PDFXrefStreamParser\n  - The PageDrawer.strokePath method is blocked, and cpu100%\n  - Avoid NPE when processing CFF2 based fonts\n  - IllegalArgumentException: Dimensions (width=458477041 height=26) are too large\n  - Can not see checkbox check\n  - NPE when converting pdf to image.\n  - NullPointerException in XMPMetadata.getSchema()\n  - PDFToImage might not correctly detect unsupported image formats\n  - Font cache isn't effective on my machine, always rebuilds\n  - PDF to Image conversion results in different converted image\n  - Text in a certain font is lost when converting pdf to image\n  - Incorrect colors in image from PDFs (DCTDecode)\n  - Inconsistent/incomplete PDF rendering\n  - Improve code quality (4)\n  - Add PDRectangle#TABLOID paper size\n  - Support version 0.5 of MaximumProfileTable\n  - loca-table isn't mandatory for TTF/OTF-fonts using CFF outlines\n  - Implement PDF 2.0 dash phase clarification\n  - Add getter and setter for the CO array under PDAcroForm\n  - Make UTC timezone static\n  - Facilitate migration to PDFBox 3.0\n  - Consolidate bouncycastle configuration\n  - Consistent scm.url values for pom.xml\n  - use comparison operators for enums\n","modified":"2026-06-10T18:24:17.654711189Z","published":"2026-06-08T14:35:58Z","related":["CVE-2026-3392","CVE-2026-33929"],"upstream":["CVE-2026-3392","CVE-2026-33929"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262046"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3392"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33929"}],"affected":[{"package":{"name":"apache-pdfbox","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/apache-pdfbox&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.36-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"apache-pdfbox":"2.0.36-160000.1.1","apache-pdfbox-javadoc":"2.0.36-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20923-1.json"}}],"schema_version":"1.7.5"}