iText is a widely embedded PDF-generation and manipulation library whose narrow product footprint masks significant supply-chain reach across enterprise applications, development platforms, and document-processing workflows. Vulnerabilities affecting the vendor skew toward serious outcomes, concentrating in its core iText library through weakness classes including XML external entity injection, resource-exhaustion conditions, command injection, and array-index validation gaps that reflect the complexity of parsing and rendering untrusted document formats. Defenders should prioritize tracking this vendor's advisories and coordinate updates across downstream products that bundle the library, since remediation often depends on application vendors rebuilding; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Itextpdf over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-43113CRITICAL iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in Ghostsc | Dec 15, 2021 | 9.8 | 33 | NO | NO |
CVE-2017-9096HIGH The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct XML external entity (XXE) attacks via a | Nov 8, 2017 | 8.8 | 33 | NO | NO |
CVE-2017-20151CRITICAL A vulnerability classified as problematic was found in iText RUPS. This vulnerability affects unknown code of the file src/main/java/com/itextpdf/rups/model/XfaFile.java. The manip | Dec 30, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-24197MEDIUM iText v7.1.17 was discovered to contain a stack-based buffer overflow via the component ByteBuffer.append, which allows attackers to cause a Denial of Service (DoS) via a crafted P | Feb 1, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-24196MEDIUM iText v7.1.17, up to (exluding)": 7.1.18 and 7.2.2 was discovered to contain an out-of-memory error via the component readStreamBytesRaw, which allows attackers to cause a Denial o | Feb 1, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-24198MEDIUM iText v7.1.17 was discovered to contain an out-of-bounds exception via the component ARCFOUREncryption.encryptARCFOUR, which allows attackers to cause a Denial of Service (DoS) via | Feb 1, 2022 | 6.5 | 22 | NO | NO |
CVE-2023-6299MEDIUM A vulnerability, which was classified as problematic, has been found in Apryse iText 8.0.1. This issue affects some unknown processing of the file PdfDocument.java of the component | Nov 26, 2023 | 6.5 | 20 | NO | NO |
CVE-2023-6298MEDIUM A vulnerability classified as problematic was found in Apryse iText 8.0.2. This vulnerability affects the function main of the file PdfDocument.java. The manipulation leads to impr | Nov 26, 2023 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Itextpdf.
Media articles that mention a CVE ID that affects a product developed by Itextpdf — matched by CVE ID, not by vendor name.