Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33929

19
FAUCET Score

CYBERSECURITY BRIEFING NOTE CVE-2026-33929 is a path traversal vulnerability in the ExtractEmbeddedFiles example component of Apache PDFBox affecting versions 2.0.24 through 2.0.36 and 3.0.0 through 3.0.7. The vulnerability stems from an incomplete remediation of a previously identified path traversal issue (CVE-2026-23907), wherein the patched code fails to properly validate file path separators. This flaw allows an attacker to write files to directories outside the intended restricted directory by exploiting improper pathname limitations. The vulnerability carries a CVSS score of 4.3 (Medium severity) with network-based attack vector, low attack complexity, and low privilege requirements. The impact is limited to integrity compromise with no confidentiality or availability concerns. The relatively low CVSS score reflects the requirement for authenticated access and the localized impact scope of file write operations. There is no evidence of active exploitation in the wild, and the vulnerability is not listed in the Known Exploited Vulnerabilities catalog. However, the issue poses a practical risk to organizations that have incorporated the vulnerable example code into production systems. Apache PDFBox has released patched versions 2.0.37 and 3.0.8, and affected users should prioritize updating while applying the referenced GitHub PR 427 fix as an interim measure if upgrades cannot be immediately deployed.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.0.24, < 2.0.37CPE matchmatch criteria
cpe:2.3:a:apache:pdfbox:*:*:*:*:*:*:*:*
>= 3.0.0, < 3.0.8CPE matchmatch criteria
cpe:2.3:a:apache:pdfbox:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.71%
Probability of exploitation in next 30 days
EPSS Percentile
49.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0071 is in the 60th percentile among its peer group of 21,951 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

github_advisorypatch availablevia nvd_reference
View patch
mavenpatch availablevia ghsa
Product: org.apache.pdfbox:pdfbox-examplesFixed in: 2.0.37
mavenpatch availablevia ghsa
Product: org.apache.pdfbox:pdfbox-examplesFixed in: 3.0.8
apachevendor investigatingvia vendor_rss
View patch

Vendor Advisories (2)

mavenGHSA-gcj8-76p4-g2fqmedium

Apache PDFBox Examples: Path Traversal in PDFBox ExtractEmbeddedFiles Example Code

Apr 14, 2026
apacheapache:www.mail-archive.com/[email protected]/msg10927.html

CVE-2026-33929: Apache PDFBox Examples: Path Traversal in PDFBox ExtractEmbeddedFiles Example Code

Apr 14, 2026

References

github.com / apache/pdfbox/pull/427/changes
Patch
lists.apache.org / thread/j8l07tgzy9dm8d8n0f3c45h7zg7t3ld6
Mailing ListVendor Advisory
lists.apache.org / thread/op3lyx1ngzy4qycn06l6hljyf28ff0zs
Mailing List