MEDIUMMaven

Apache PDFBox has Path Traversal through PDComplexFileSpecification.getFilename() function

Apache PDFBox has Path Traversal through PDComplexFileSpecification.getFilename() function

CVE-2026-23907Published 6 months agoUpdated 5 days agoSource: OSV

Affected packages

  • org.apache.pdfbox:pdfbox-examples2.0.24 → 3.0.7

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

Apache PDFBox has Path Traversal through PDComplexFileSpecification.getFilename() function | HackTribune