{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-33929",
        "tracking": {
            "current_release_date": "2026-08-19T09:56:21.992953Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-33929",
            "initial_release_date": "2026-04-14T07:35:21.579025Z",
            "revision_history": [
                {
                    "date": "2026-04-14T07:35:21.579025Z",
                    "number": "1",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-04-14T09:14:29.724757Z",
                    "number": "2",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| Products connected (2).| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-04-14T09:14:36.452330Z",
                    "number": "3",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-04-14T09:26:33.280330Z",
                    "number": "4",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-04-14T09:26:42.990419Z",
                    "number": "5",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-04-14T12:44:08.597070Z",
                    "number": "6",
                    "summary": "Source created.| CVE status created. (valid)| Products connected (4)."
                },
                {
                    "date": "2026-04-14T12:44:16.409627Z",
                    "number": "7",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-04-14T20:27:12.222684Z",
                    "number": "8",
                    "summary": "CVSS created."
                },
                {
                    "date": "2026-04-14T20:27:16.220776Z",
                    "number": "9",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-04-14T20:48:03.627861Z",
                    "number": "10",
                    "summary": "CVSS created.| Unknown change."
                },
                {
                    "date": "2026-04-14T20:48:06.133802Z",
                    "number": "11",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-04-15T00:42:13.835920Z",
                    "number": "12",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (5).| CWES updated (1)."
                },
                {
                    "date": "2026-04-15T00:42:27.136914Z",
                    "number": "13",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-04-15T02:18:25.691170Z",
                    "number": "14",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-04-15T02:18:28.654800Z",
                    "number": "15",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-04-15T06:44:09.237645Z",
                    "number": "16",
                    "summary": "Description created for source."
                },
                {
                    "date": "2026-04-15T06:44:26.508528Z",
                    "number": "17",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-04-16T00:28:11.148877Z",
                    "number": "18",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (16).| Product Identifiers created (8).| References created (5).| CWES updated (1).| Vendor_assessment created."
                },
                {
                    "date": "2026-04-16T00:28:14.711709Z",
                    "number": "19",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-04-20T20:37:15.072469Z",
                    "number": "20",
                    "summary": "Products created (2).| Product Identifiers created (2)."
                },
                {
                    "date": "2026-04-20T20:37:18.500047Z",
                    "number": "21",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-04-21T16:01:09.231031Z",
                    "number": "22",
                    "summary": "EPSS updated."
                },
                {
                    "date": "2026-04-21T16:01:12.626448Z",
                    "number": "23",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-05-02T11:53:35.794974Z",
                    "number": "24",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (23).| Product Identifiers created (21).| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-05-02T11:53:46.795193Z",
                    "number": "25",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-05-27T12:06:15.764614Z",
                    "number": "26",
                    "summary": "Source connected.| CVE status created. (valid)| Products connected (1).| References created (3)."
                },
                {
                    "date": "2026-05-27T12:06:17.629759Z",
                    "number": "27",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-05-29T16:55:12.473177Z",
                    "number": "28",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-05-29T16:55:14.652476Z",
                    "number": "29",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-06-15T15:03:56.374266Z",
                    "number": "30",
                    "summary": "EPSS updated."
                },
                {
                    "date": "2026-06-15T15:03:58.144657Z",
                    "number": "31",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-06-16T18:47:48.902444Z",
                    "number": "32",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| Products connected (2).| References created (4)."
                },
                {
                    "date": "2026-06-16T18:47:50.679732Z",
                    "number": "33",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-12T12:06:21.967203Z",
                    "number": "34",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (6).| CWES updated (1)."
                },
                {
                    "date": "2026-07-12T12:06:28.057714Z",
                    "number": "35",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-22T19:40:35.013307Z",
                    "number": "36",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-07-22T19:40:42.681136Z",
                    "number": "37",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-19T07:17:19.656043Z",
                    "number": "38",
                    "summary": "Source connected.| CVE status created. (valid)| Products connected (5).| References created (3)."
                },
                {
                    "date": "2026-08-19T07:17:30.078658Z",
                    "number": "39",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-19T09:56:19.097649Z",
                    "number": "40",
                    "summary": "Source connected.| CVE status created. (valid)"
                }
            ],
            "status": "interim",
            "version": "40"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/2.0.24|<=2.0.36",
                                "product": {
                                    "name": "vers:semver/2.0.24|<=2.0.36",
                                    "product_id": "CSAFPID-5774304"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/3.0.0|<=3.0.7",
                                "product": {
                                    "name": "vers:semver/3.0.0|<=3.0.7",
                                    "product_id": "CSAFPID-5774305"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Apache PDFBox Examples"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=2.0.24|<2.0.37",
                                "product": {
                                    "name": "vers:unknown/>=2.0.24|<2.0.37",
                                    "product_id": "CSAFPID-6175224",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:apache:pdfbox:*:*:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=3.0.0|<3.0.8",
                                "product": {
                                    "name": "vers:unknown/>=3.0.0|<3.0.8",
                                    "product_id": "CSAFPID-6175225",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:apache:pdfbox:*:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "PDFBox"
                    }
                ],
                "category": "vendor",
                "name": "Apache Software Foundation"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.0.8.0",
                                "product": {
                                    "name": "vers:unknown/8.0.8.0",
                                    "product_id": "CSAFPID-9011234",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:oracle:financial_services_applications:8.0.8.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.0.8.1",
                                "product": {
                                    "name": "vers:unknown/8.0.8.1",
                                    "product_id": "CSAFPID-1846999",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:oracle:financial_services_applications:8.0.8.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.0.8.2",
                                "product": {
                                    "name": "vers:unknown/8.0.8.2",
                                    "product_id": "CSAFPID-6213321",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:oracle:financial_services_applications:8.0.8.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.1.2.11",
                                "product": {
                                    "name": "vers:unknown/8.1.2.11",
                                    "product_id": "CSAFPID-6213320",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:oracle:financial_services_applications:8.1.2.11"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.1.3.1",
                                "product": {
                                    "name": "vers:unknown/8.1.3.1",
                                    "product_id": "CSAFPID-8878808",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:oracle:financial_services_applications:8.1.3.1"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Financial Services Applications"
                    }
                ],
                "category": "vendor",
                "name": "Oracle"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.2",
                                "product": {
                                    "name": "vers:unknown/9.2",
                                    "product_id": "CSAFPID-165054",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:ibm:license_metric_tool:9.2"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "License Metric Tool"
                    }
                ],
                "category": "vendor",
                "name": "IBM"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/7",
                                "product": {
                                    "name": "vers:rpm/7",
                                    "product_id": "CSAFPID-1439334",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:amq_broker:7"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat AMQ Broker 7"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/8",
                                "product": {
                                    "name": "vers:rpm/8",
                                    "product_id": "CSAFPID-1439292",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:jboss_data_grid:8"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Data Grid 8"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/7",
                                "product": {
                                    "name": "vers:rpm/7",
                                    "product_id": "CSAFPID-1439294",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:jboss_fuse:7"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Fuse 7"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/7",
                                "product": {
                                    "name": "vers:rpm/7",
                                    "product_id": "CSAFPID-1439300",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat JBoss Enterprise Application Platform 7"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/8",
                                "product": {
                                    "name": "vers:rpm/8",
                                    "product_id": "CSAFPID-1439302",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:8"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat JBoss Enterprise Application Platform 8"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/unknown",
                                "product": {
                                    "name": "vers:rpm/unknown",
                                    "product_id": "CSAFPID-1439304",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:jbosseapxp"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/4",
                                "product": {
                                    "name": "vers:rpm/4",
                                    "product_id": "CSAFPID-1439286",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:camel_spring_boot:4"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat build of Apache Camel for Spring Boot 4"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5794339"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pdfbox"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat AMQ Broker 7"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5794343"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pdfbox"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Data Grid 8"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5794344"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pdfbox"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Fuse 7"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5794346"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pdfbox"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat JBoss Enterprise Application Platform 7"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5794348"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pdfbox"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat JBoss Enterprise Application Platform 8"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5794351"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pdfbox"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5794340"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pdfbox"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat build of Apache Camel for Spring Boot 4"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5794354"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pdfbox"
                            }
                        ],
                        "category": "product_family",
                        "name": "streams for Apache Kafka 2"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/2",
                                "product": {
                                    "name": "vers:rpm/2",
                                    "product_id": "CSAFPID-2467457",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:amq_streams:2"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "streams for Apache Kafka 2"
                    }
                ],
                "category": "vendor",
                "name": "Red Hat"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0|<2.0.36-160000.1.1",
                                        "product": {
                                            "name": "vers:unknown/>=0|<2.0.36-160000.1.1",
                                            "product_id": "CSAFPID-8467863"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "apache-pdfbox"
                            }
                        ],
                        "category": "product_family",
                        "name": "SUSE:Linux Enterprise Server 16.0"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0|<2.0.36-160000.1.1",
                                        "product": {
                                            "name": "vers:unknown/>=0|<2.0.36-160000.1.1",
                                            "product_id": "CSAFPID-8467864"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "apache-pdfbox"
                            }
                        ],
                        "category": "product_family",
                        "name": "SUSE:Linux Enterprise Server for SAP applications 16.0"
                    }
                ],
                "category": "vendor",
                "name": "SUSE"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/unknown",
                                        "product": {
                                            "name": "vers:deb/unknown",
                                            "product_id": "CSAFPID-1394038"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "libpdfbox-java"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/unknown",
                                        "product": {
                                            "name": "vers:deb/unknown",
                                            "product_id": "CSAFPID-5810402"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "libpdfbox2-java"
                            }
                        ],
                        "category": "product_family",
                        "name": "bookworm"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/unknown",
                                        "product": {
                                            "name": "vers:deb/unknown",
                                            "product_id": "CSAFPID-1394039"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "libpdfbox-java"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/unknown",
                                        "product": {
                                            "name": "vers:deb/unknown",
                                            "product_id": "CSAFPID-1394041"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "libpdfbox2-java"
                            }
                        ],
                        "category": "product_family",
                        "name": "bullseye"
                    }
                ],
                "category": "vendor",
                "name": "Debian"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.24",
                                "product": {
                                    "name": "vers:unknown/2.0.24",
                                    "product_id": "CSAFPID-6450947",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.pdfbox/pdfbox-examples@2.0.24"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.25",
                                "product": {
                                    "name": "vers:unknown/2.0.25",
                                    "product_id": "CSAFPID-6450948",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.pdfbox/pdfbox-examples@2.0.25"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.26",
                                "product": {
                                    "name": "vers:unknown/2.0.26",
                                    "product_id": "CSAFPID-6450949",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.pdfbox/pdfbox-examples@2.0.26"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.27",
                                "product": {
                                    "name": "vers:unknown/2.0.27",
                                    "product_id": "CSAFPID-6450950",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.pdfbox/pdfbox-examples@2.0.27"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.28",
                                "product": {
                                    "name": "vers:unknown/2.0.28",
                                    "product_id": "CSAFPID-6450951",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.pdfbox/pdfbox-examples@2.0.28"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.29",
                                "product": {
                                    "name": "vers:unknown/2.0.29",
                                    "product_id": "CSAFPID-6450952",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.pdfbox/pdfbox-examples@2.0.29"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.30",
                                "product": {
                                    "name": "vers:unknown/2.0.30",
                                    "product_id": "CSAFPID-6450953",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.pdfbox/pdfbox-examples@2.0.30"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.31",
                                "product": {
                                    "name": "vers:unknown/2.0.31",
                                    "product_id": "CSAFPID-6450954",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.pdfbox/pdfbox-examples@2.0.31"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.32",
                                "product": {
                                    "name": "vers:unknown/2.0.32",
                                    "product_id": "CSAFPID-6450955",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.pdfbox/pdfbox-examples@2.0.32"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.33",
                                "product": {
                                    "name": "vers:unknown/2.0.33",
                                    "product_id": "CSAFPID-6450956",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.pdfbox/pdfbox-examples@2.0.33"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.34",
                                "product": {
                                    "name": "vers:unknown/2.0.34",
                                    "product_id": "CSAFPID-6450957",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.pdfbox/pdfbox-examples@2.0.34"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.35",
                                "product": {
                                    "name": "vers:unknown/2.0.35",
                                    "product_id": "CSAFPID-6450958",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.pdfbox/pdfbox-examples@2.0.35"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.36",
                                "product": {
                                    "name": "vers:unknown/2.0.36",
                                    "product_id": "CSAFPID-6450959",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.pdfbox/pdfbox-examples@2.0.36"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.0",
                                "product": {
                                    "name": "vers:unknown/3.0.0",
                                    "product_id": "CSAFPID-6450961",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.pdfbox/pdfbox-examples@3.0.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.1",
                                "product": {
                                    "name": "vers:unknown/3.0.1",
                                    "product_id": "CSAFPID-6450962",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.pdfbox/pdfbox-examples@3.0.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.2",
                                "product": {
                                    "name": "vers:unknown/3.0.2",
                                    "product_id": "CSAFPID-6450963",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.pdfbox/pdfbox-examples@3.0.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.3",
                                "product": {
                                    "name": "vers:unknown/3.0.3",
                                    "product_id": "CSAFPID-6450964",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.pdfbox/pdfbox-examples@3.0.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.4",
                                "product": {
                                    "name": "vers:unknown/3.0.4",
                                    "product_id": "CSAFPID-6450965",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.pdfbox/pdfbox-examples@3.0.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.5",
                                "product": {
                                    "name": "vers:unknown/3.0.5",
                                    "product_id": "CSAFPID-6450966",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.pdfbox/pdfbox-examples@3.0.5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.6",
                                "product": {
                                    "name": "vers:unknown/3.0.6",
                                    "product_id": "CSAFPID-6450967",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.pdfbox/pdfbox-examples@3.0.6"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.7",
                                "product": {
                                    "name": "vers:unknown/3.0.7",
                                    "product_id": "CSAFPID-6450968",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.apache.pdfbox/pdfbox-examples@3.0.7"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=2.0.24|<2.0.37",
                                "product": {
                                    "name": "vers:unknown/>=2.0.24|<2.0.37",
                                    "product_id": "CSAFPID-6450960"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=3.0.0|<3.0.8",
                                "product": {
                                    "name": "vers:unknown/>=3.0.0|<3.0.8",
                                    "product_id": "CSAFPID-6450969"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "pdfbox-examples"
                    }
                ],
                "category": "vendor",
                "name": "apache"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-33929",
            "cwe": {
                "id": "CWE-22",
                "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache PDFBox Examples.\n\nThis issue affects the \nExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.36, from 3.0.0 through 3.0.7.\n\n\nUsers are recommended to update to version 2.0.37 or 3.0.8 once \navailable. Until then, they should apply the fix provided in GitHub PR \n427.\n\nThe ExtractEmbeddedFiles example contained a path traversal vulnerability (CWE-22) mentioned in CVE-2026-23907. However the change in the releases 2.0.36 and 3.0.7 is flawed because it doesn't consider the file path separator. Because of that, a user having writing rights on /home/ABC could be victim to a malicious PDF resulting in a write attempt to any path starting with /home/ABC, e.g. \"/home/ABCDEF\".\n\nUsers who have copied this example into their production code should apply the mentioned change. The example \nhas been changed accordingly and is available in the project repository.",
                    "title": "cveprojectv5 - https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/33xxx/CVE-2026-33929.json"
                },
                {
                    "category": "description",
                    "text": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache PDFBox Examples.\n\nThis issue affects the \nExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.36, from 3.0.0 through 3.0.7.\n\n\nUsers are recommended to update to version 2.0.37 or 3.0.8 once \navailable. Until then, they should apply the fix provided in GitHub PR \n427.\n\nThe ExtractEmbeddedFiles example contained a path traversal vulnerability (CWE-22) mentioned in CVE-2026-23907. However the change in the releases 2.0.36 and 3.0.7 is flawed because it doesn't consider the file path separator. Because of that, a user having writing rights on /home/ABC could be victim to a malicious PDF resulting in a write attempt to any path starting with /home/ABC, e.g. \"/home/ABCDEF\".\n\nUsers who have copied this example into their production code should apply the mentioned change. The example \nhas been changed accordingly and is available in the project repository.",
                    "title": "nvd - https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-33929"
                },
                {
                    "category": "description",
                    "text": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache PDFBox Examples.\n\nThis issue affects the \nExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.36, from 3.0.0 through 3.0.7.\n\n\nUsers are recommended to update to version 2.0.37 or 3.0.8 once available. Until then, they should apply the fix provided in GitHub PR 427.\n\nThe ExtractEmbeddedFiles example contained a path traversal vulnerability (CWE-22) mentioned in CVE-2026-23907. However the change in the releases 2.0.36 and 3.0.7 is flawed because it doesn't consider the file path separator. Because of that, a user having writing rights on /home/ABC could be victim to a malicious PDF resulting in a write attempt to any path starting with /home/ABC, e.g. \"/home/ABCDEF\".\n\nUsers who have copied this example into their production code should apply the mentioned change. The example \nhas been changed accordingly and is available in the project repository.",
                    "title": "github - https://api.github.com/advisories/GHSA-gcj8-76p4-g2fq"
                },
                {
                    "category": "description",
                    "text": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache PDFBox Examples.  This issue affects the  ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.36, from 3.0.0 through 3.0.7.   Users are recommended to update to version 2.0.37 or 3.0.8 once  available. Until then, they should apply the fix provided in GitHub PR  427.  The ExtractEmbeddedFiles example contained a path traversal vulnerability (CWE-22) mentioned in CVE-2026-23907. However the change in the releases 2.0.36 and 3.0.7 is flawed because it doesn't consider the file path separator. Because of that, a user having writing rights on /home/ABC could be victim to a malicious PDF resulting in a write attempt to any path starting with /home/ABC, e.g. \"/home/ABCDEF\".  Users who have copied this example into their production code should apply the mentioned change. The example  has been changed accordingly and is available in the project repository.",
                    "title": "debian - https://security-tracker.debian.org/tracker/CVE-2026-33929"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in Apache PDFBox. A local user with writing rights to a specific directory could be exploited via a malicious PDF file when using the ExtractEmbeddedFiles example. This path traversal (CWE-22) vulnerability, which allows an attacker to access files and directories outside of the intended directory, enables arbitrary file write attempts.",
                    "title": "redhat - https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-33929.json"
                },
                {
                    "category": "description",
                    "text": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache PDFBox Examples.\n\nThis issue affects the \nExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.36, from 3.0.0 through 3.0.7.\n\n\nUsers are recommended to update to version 2.0.37 or 3.0.8 once available. Until then, they should apply the fix provided in GitHub PR 427.\n\nThe ExtractEmbeddedFiles example contained a path traversal vulnerability (CWE-22) mentioned in CVE-2026-23907. However the change in the releases 2.0.36 and 3.0.7 is flawed because it doesn't consider the file path separator. Because of that, a user having writing rights on /home/ABC could be victim to a malicious PDF resulting in a write attempt to any path starting with /home/ABC, e.g. \"/home/ABCDEF\".\n\nUsers who have copied this example into their production code should apply the mentioned change. The example \nhas been changed accordingly and is available in the project repository.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Maven%2FGHSA-gcj8-76p4-g2fq.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "This update for apache-pdfbox fixes the following issues:\n\nUpdate to version 2.0.36.\n\nSecurity issues fixed:\n\n- CVE-2026-33929: path traversal in the `ExtractEmbeddedFiles` example code can lead to arbitrary file writes\n  (bsc#1262046).\n\nOther updates and bugfixes:\n\n- Version 2.0.36:\n  - XMPBox removes namespaces on serialization\n  - False negative on PDFA-1b validation : missing field type\n  - PlainText.Paragraph.getLines extremely slow on long lines\n  - Valid PDF/A 1B is rejected\n  - Potential StackOverflows in BaseParser\n  - Unknown code in Huffman RLE stream\n  - IllegalArgumentException: Can't add attribute to 0-length text\n  - TTFSubsetter.buildGlyfTable() modifies glyphIds while iterating over its entries possibly causing\n    ConcurrentModificationException to be thrown\n  - IndexOutOfBoundsException in Type1CharStringParser.processCallSubr()\n  - Exception \"No type defined for {http://www.aiim.org/pdfa/ns/id/}rev\" when trying to determine version of PDF/A-4\n    document\n  - allow new PDF/A-4 conformance levels\n  - pdfbox-app-X.X.X-sources.jar on maven central are empty (and javadoc jar is missing)\n  - Cmd line docs\n  - IllegalArgumentException: Multiplying two matrices produces illegal values in PDFStreamEngine.processAnnotation()\n  - XmpParsingException: Schema is not set in this document: http://ns.adobe.com/xap/1.0/sType/ResourceEvent#\n  - NullPointerException in FontMapperImpl.getFontMatches()\n  - border style in FDFAnnotation is not initialized if width is 0\n  - German umlauts are not rendered\n  - Invalid type in Schema not detected when in XML attributes\n  - Serializing produces date \"1-01-01T00:00:00+01:00\"\n  - Seconds of date \"D:2015-02-03T10:11:12\" returned as 0\n  - Confusing naming of \"DerivedFrom\" property getter in XMPMediaManagementSchema\n  - ClassCastException in XMPMediaManagementSchema.getHistory()\n  - IllegalArgumentException: Input buffer too short in StandardSecurityHandler.computeRC4key()\n  - IllegalArgumentException: Width (0) and height (0) cannot be <= 0 when printing landscape rotated with\n    RASTERIZE_DPI_AUTO\n  - DateConverter fails on valid date\n  - ClassCastException: class org.apache.xmpbox.type.TextType cannot be cast to class\n    org.apache.xmpbox.type.ArrayProperty in DublinCoreSchema.getCreatorsProperty()\n  - tiff:YCbCrSubSampling and tiff:YCbCrPositioning have wrong cardinality\n  - ClassCastException: class org.apache.xmpbox.type.FlashType\n  - Cannot find a definition for the namespace http://www.w3.org/1999/02/22-rdf-syntax-ns#, property:\n    rdf:Description http://ns.adobe.com/xap/1.0/sType/ResourceEvent#, property:stEvt:action\n  - XmpParsingException: Missing pdfaSchema:property in type definition in lenient mode\n  - XmpParsingException: Unknown property value type : Open Choice of Integer\n  - XmpParsingException: Property 'CountryCode' not defined in http://www.epo.org/patent-bibliographic-data/1.0/\n  - date \"0-00-00T00:00:00-04:00\" read as \"0002-11-30T00:00:00-40:00\"\n  - XmpParsingException: Type 'stRef:documentName' not defined in http://ns.adobe.com/xap/1.0/sType/ResourceRef# in\n    lenient mode\n  - Invalid PDF/A namespace definition, prefix: xmlns, namespace: http://www.aiim.org/pdfa/ns/extension/\n    http://www.aiim.org/pdfa/ns/extension/, property: pdfaExtension:schemas\n  - NegativeArraySizeException in PredictorOutputStream()\n  - NullpointerException in PDAcroForm.getField(Line 485)\n  - OutOfMemoryError when trying to extract text from pdf\n  - Outlines circular reference vulnerability\n  - Rendered text missing\n  - Inverted images due to enlarged decode array\n  - PDF displays garbled characters in Adobe Reader but renders correctly in web browsers\n  - NullPointerException while merging PDFs with output intents\n  - Valid XMP Extension Schema rejected\n  - Remove dead code from PDFMarkedContentExtractor\n  - Include test file in test class\n  - Get and Add PageTextSchema\n  - Remove / deprecate TypeMapping.getAssociatedSchemaObject()\n  - Support Seq / Bag mixup in lenient mode\n  - Parse xmp files in lenient mode that have no processing instructions\n  - deprecate getPDFIdentificationSchema() in favor of getPDFAIdentificationSchema()\n  - Support TIFF-files with FillOrder=2 conversion to PDF\n  - Remove / deprecate unused parts of PDIndexed\n  - modernize rat exclusions\n- Version 2.0.35:\n  - NegativeArraySizeException with PDF file with huge fonts\n  - Inline image bug with multi-byte newline tokens\n  - fix initial ByteArrayOutputStream size for deflate operation\n  - PDF takes an hour to render\n  - Splitter does not include structure tree in documents past the first split\n  - build fails on jdk11\n  - Load a TTF font which is from Mac OS throw an exception\n  - Wrong glyphs since PDFBOX-5790\n  - ClassCastException on broken file in PDEmbeddedFilesNameTreeNode.convertCOSToPD()\n  - invalid XMP generated when Apache Xalan in the classpath\n  - XMP JobType constructor ignores fieldPrefix\n  - NullPointerException in xmpbox serializer if a date is empty\n  - Rendering issue with type 2 shading: vertical expansion\n  - Possible infinite loop in shading code\n  - Potential OOM in XrefStreamParser\n  - Potential StackOverflow in PDFStreamParser\n  - Potential StackOverflow in PDPageTree's getInheritableAttribute\n  - Potential OOM in Type1Lexer\n  - Potential OOM in PfbParser\n  - PDMarkedContentReference.setMCID() should not accept negative numbers\n  - IllegalPathStateException: missing initial moveto in path definition\n  - Fix possible ClassCastException\n  - NullPointerException in COSDictionary\n  - StringIndexOutOfBoundsException in PlainText$Paragraph.getLines()\n  - LZWFilter crashes, probably not handling the KwKwK special case\n  - NullPointerException in PDNumberTreeNode.getNumbers()\n  - UnsupportedOperationException: JPX color spaces don't support drawing\n  - Signing tries to set byteRange of old signature (2)\n  - ClassCastException in PDOptionalContentProperties.getBaseState()\n  - Add test for embedded files\n  - set size for ByteArrayOutputStreams\n  - avoid creation of temporary objects when parsing hex values\n  - avoid unnecessary map lokups\n  - remove unnecessary iteration and StringBuilder creation\n  - Support reverse landscape orientation for printing\n  - Add test coverage for orphan annotation\n  - Remove orphan popup parent annotation\n  - Improve XmpSerializer test by verifying its output\n  - Consider rotation of page when applying overlay\n  - Preserve Perms dictionary when signing\n  - Check /ParentTree against /K tree\n  - Add test for 5521\n  - Refactor RC4Cipher\n  - Regression tests for 2.0.35\n- Version 2.0.34:\n  - PageDrawer is not rendering unrotatable Annotations on rotated pages\n  - Zero-width non-joiner characters visible in generated PDF\n  - Surrogate pairs with combining diacritics are incorrectly ordered on text extraction\n  - TestCreateSignature.testCreateSignedTimeStamp checkLTV build test fail (2) / Support several issuers\n  - IllegalArgumentException: Width (0) and height (0) must be non-zero\n  - Merge docs with specific characteristics causes stack overflow - InvalidKeyException: Supplied key\n   (sun.security.ec.ECPrivateKeyImpl) is not a RSAPrivateKey\n  - Can't read the embedded Type1 font: Found Token[kind=NAME,text=def] but expected begin\n  - Wrong size entry in trailer after incremental save\n  - FileSystemFontProvider doesn't register failed type1 fonts\n  - Text annotation crosshair symbol too small when using Adobe symbol font\n  - Orphan /OpenAction destination page kept in merge\n  - PDFRenderer causes endless loop\n  - Invalid stream length: 0, stream start position: <xxx>\n  - Inline image incorrectly parsed (2)\n  - IllegalArgumentException: Not a valid Unicode code point: 0xE28496\n  - Type 3 font glyphs not displayed\n  - Rendered PDF is missing shading pattern graphics\n  - NPE during merge\n  - Class cast exception in building PDDestinationNameTreeNode\n  - DomXmpParser incorrectly expects namespaces on attribute level\n  - BDC processor mishandles property name\n  - Can't render some Type1C fonts.\n  - PDF to Image conversion results in a blank white page\n  - Implement PDFormXObject.setGroup()\n  - CertificateVerifier.isSelfSigned() should not throw an exception\n  - Use Zapf Dingbats code for cross text annotation\n  - Support PushPin, Tag and Graph file attachment annotation icons\n  - Improve PDFMergerUtility memory footprint\n  - Support rare RC4 encryption where R=4, key length < 128 bits\n  - Improve checkWithNumberTree() test\n  - Use SHA256 instead of MD5 for document id\n- Version 2.0.33:\n  - Character positions shifted\n  - Incorrectly extracted text (broken words)\n  - Wrong color of uncolored tiling pattern\n  - OutOfMemoryError - during renderImageWithDPI\n  - BaseParser fails when a number is followed by a string starting with 'e'\n  - Type3 font is not rendered\n  - Flattening removes all annotations when widget annotation has no page\n  - Image lost on page render\n  - extra whitespaces when extracting Arabic text\n  - SMaskInData not supported for JPX images\n  - Kid Widget /DA is ignored in setDefaultAppearance() call\n  - Radio button can't be set\n  - the PDDocument.documentId does not seem to be written into the flat byteStream\n  - PDFBox is unable to remove ID\n  - Fix last step of the build process\n  - StringIndexOutOfBoundsException in AppearanceGeneratorHelper\n  - ClassCastException in SetLineJoinStyle.process()\n  - Unable to load password protected pdf\n  - PDFBox not extracting text of non-latin languages(tamil, bengali) properly but adobe reader's save as text does\n  - Checkstyle\n  - [PATCH] Detect CMYK image without relying on metadata\n  - Regression from PDFBOX-5841: Text extraction with rotation magic fails for PDF with multiple content streams in a\n    page\n  - PDF render blank page: The end of the stream doesn't point to the correct offset, using workaround to read the\n    stream, stream start position: 196, length: 0, expected end position: 196\n  - CVE for Lucene libraries\n  - The pattern created with PDFBox shows inconsistent colors between Safari and Adobe.\n  - BDC sequence with resource reference instead of with MCID\n  - StackOverflowError in PDFieldFactory.findFieldType\n  - ClassCastException in AnnotationValidator\n  - The CPU usage of a PDF file with a size of 85.6 MB is abnormal\n  - Many ZapfDingbats symbols do not appear when page is rendered.\n  - IOException when reading isolated \"+\"\n  - IllegalArgumentException: capacity < 0: (-75475220 < 0) in RandomAccessReadBuffer constructor\n  - FontBox spawns a `cmd` subprocess to read an environment variable (on Windows)\n  - Implement PDF 2.0 dash phase clarification (2)\n  - Particular PDF fails on renderImageWithDPI call\n  - PDType0Font return invalid space width\n  - Icons of text annotations sometimes too large\n  - Orphan page check doesn't check annotation destinations\n  - NPE in COSArray.indexOfObject\n  - NPE in PagePane.mouseMoved()\n  - ArrayIndexOutOfBoundsException in CMap.toInt()\n  - Show ASN.1 decoded Contents for Signature-Dictionary\n  - Exchange hard-coded values for variables and provide command-line options in TextToPDF component\n  - Long rendering time of fonts in a specific PDF\n  - Support imageio-jnr / imageio-openjpeg library for JPEG2000 decoding\n  - Improve ExtractTTFFonts\n  - Change Loglevel from Warn to info when rebuilding font cache\n  - Support OCG visibility expressions\n  - Add page getter/setter to PDObjectReference\n  - Support long values for COSInteger objects\n  - Empty constructor for PDViewerPreferences\n  - Add check of /P to PDFMergerUtilityTest\n  - support Markdown extraction from the command line\n  - Calculate dpi dynamically when printing with raster\n  - Remove orphan annotations in structure tree\n  - Add font name to PrintTextLocations\n  - Improve detection whether printing or viewing\n  - Hi CPU and memory usage when converting a PDF with type 4 shading\n  - 2.0 builds fail on jenkins because jdk11 no longer supported\n- Version 2.0.32:\n  - preflight-app fails on Java 11+ with NoClassDefFoundError: javax/activation/DataSource\n  - AppearanceGeneratorHelper assumes fontscale 1000\n  - Remove release subproject\n  - Don't use a predefined CMap if a ToUnicode CMap is present\n  - Regression NPE in Splitter\n  - The content of the specified font is lost, Google Chrome can display it\n  - Crash for Softmask with incorrect backdrop color components\n  - Observable Timing Discrepancy (Timing Attack)\n  - Black rectangle over image\n  - Wrong font substitution for Wingdings\n  - PDDocument#importPage slowed down by factor 1300\n  - Split aborts with broken destinations\n  - IllegalArgumentException: Parameter must be 1-based, but is 0 when using PDFTextStripperByArea\n  - Files created with PDFMergerExample are not correct PDF/A\n  - Missing /Subtype and /Type in Metadata not detected\n  - Multiple exceptions coming from org.apache.fontbox.ttf for different PDFs\n  - IOException: Error expected floating point numberactual='-12.-1'\n  - NullPointerException: Cannot invoke \"String.codePointAt(int)\" because \"uni\" is null\n  - DomXmpParser - IllegalArgumentException: prefix cannot be \"null\" when creating a QName\n  - ClassCastException: org.apache.pdfbox.cos.COSNull cannot be cast to org.apache.pdfbox.cos.COSDictionary\n  - IllegalArgumentException: Width (26) and height (0) must be non-zero\n  - There is an exception when getting embedded font, is it compatible?\n  - Infinite loop after splitting and saving PDF / giant result files\n  - JPEGFactory. Reduce logging severity when no image metadata is present\n  - Add test for surrogate pair character ð© ̧1⁄2\n  - Update unicode Scripts.txt\n  - Include a PDFA check with VeraPDF for CreatePDFATest\n  - Add center constructor parameter to PDFPageable and to pdfbox-app\n  - When splitting, keep named page destinations that are part of target document(s)\n  - When this PDF is rendered with the \"f\" Operator, a black screen appears.\n  - Investigate why we get \"response contains wrong nonce value\" during build tests\n- Version 2.0.31:\n  - [PATCH] Split pdf lose accessibility tags\n  - Allow creating of PDFXObjectImage without accessing to the image stream\n  - PfbParser fails to parse PFB font with multiple binary records.\n  - Lines vanish when printing on MacOS\n  - java.lang.IllegalArgumentException: Provided dictionary is not of type 'COSName{OCG}'\n  - The embedded font DroidSansFallbackFull reports an error when parsing, and finally uses lastResortFont, resulting in\n    garbled fonts.\n  - COSName caches already cached hashCode\n  - Font operation takes a long time with 3.0.1\n  - NullPointerException in TTFSubsetter.buildPostTable()\n  - Problem converting PDF to image (java.awt.color.CMMException: Can not access specified profile)\n  - Set the default value for PDNonTerminalField\n  - java.lang.ArrayIndexOutOfBoundsException Bug Report\n  - Wrong colors in PDF since PDFBOX-5488\n  - Java 7 support on 2.0\n  - Convert to image exception\n  - PDF conversion in this format is very slow. Is there any room for optimization?\n  - IllegalArgumentException: -Infinity is not a finite number\n  - Inconsistent signature page handling when signing in existing  signature fields\n  - Add leading \"0\" for octal values in MacOSRomanEncoding\n  - DataFormatException: invalid distance too far back\n  - Grayscale JPEG rendered multicolor\n  - OutOfMemoryError in FileSystemFontsProvider.scanFonts\n  - NPE in PageDrawer.getPaint()\n  - Issue with embedded Font and descendant Font\n  - LCMS error 13: Mismatched alpha channels\n  - Enable Native Markdown Extraction in Apache PDFBox\n  - When splitting, keep page destinations that are part of target document(s)\n  - Replace Exception with some repair attempt\n- Version 2.0.30:\n  - Regression unicode mapping in Korean document\n  - Operators \"q\" and \"Q\" should also preserve text matrices\n  - Signature Image not Rendered starting with PDFBox 2.0.23\n  - Fonts are not subsetted when saving incrementally\n  - Bug in PDFMergerUtility#mergeFields\n  - Password protected PDF opens in GUI apps but PDFbox says invalid password\n  - Wrong error message \"2.4.1 : Invalid Color space, The operator \"rg\" can't be used with CMYK Profile\"\n  - Make FDF annotations more compliant with the specification\n  - NPE in DomXmpParser.parseLiDescription\n  - Regression: NoSuchElementException in PDFXrefStreamParser\n  - The PageDrawer.strokePath method is blocked, and cpu100%\n  - Avoid NPE when processing CFF2 based fonts\n  - IllegalArgumentException: Dimensions (width=458477041 height=26) are too large\n  - Can not see checkbox check\n  - NPE when converting pdf to image.\n  - NullPointerException in XMPMetadata.getSchema()\n  - PDFToImage might not correctly detect unsupported image formats\n  - Font cache isn't effective on my machine, always rebuilds\n  - PDF to Image conversion results in different converted image\n  - Text in a certain font is lost when converting pdf to image\n  - Incorrect colors in image from PDFs (DCTDecode)\n  - Inconsistent/incomplete PDF rendering\n  - Improve code quality (4)\n  - Add PDRectangle#TABLOID paper size\n  - Support version 0.5 of MaximumProfileTable\n  - loca-table isn't mandatory for TTF/OTF-fonts using CFF outlines\n  - Implement PDF 2.0 dash phase clarification\n  - Add getter and setter for the CO array under PDAcroForm\n  - Make UTC timezone static\n  - Facilitate migration to PDFBox 3.0\n  - Consolidate bouncycastle configuration\n  - Consistent scm.url values for pom.xml\n  - use comparison operators for enums\n",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/SUSE%2FSUSE-SU-2026:22088-1.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache PDFBox Examples.\n\nThis issue affects the \nExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.36, from 3.0.0 through 3.0.7.\n\n\nUsers are recommended to update to version 2.0.37 or 3.0.8 once \navailable. Until then, they should apply the fix provided in GitHub PR \n427.\n\nThe ExtractEmbeddedFiles example contained a path traversal vulnerability (CWE-22) mentioned in CVE-2026-23907. However the change in the releases 2.0.36 and 3.0.7 is flawed because it doesn't consider the file path separator. Because of that, a user having writing rights on /home/ABC could be victim to a malicious PDF resulting in a write attempt to any path starting with /home/ABC, e.g. \"/home/ABCDEF\".\n\nUsers who have copied this example into their production code should apply the mentioned change. The example \nhas been changed accordingly and is available in the project repository.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-33929.json?alt=media"
                },
                {
                    "category": "other",
                    "text": "0.00711",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "4.9",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "There is product data available from source Certbundde, The value of the most recent EPSS score",
                    "title": "NCSC Score top increasing factors"
                },
                {
                    "category": "other",
                    "text": "There is cwe data available from source Github, The value of the most recent CVSS (V3) score, Is related to a product by vendor Apache, Is related to a product by vendor Ibm",
                    "title": "NCSC Score top decreasing factors"
                },
                {
                    "category": "details",
                    "text": "Severity: 2\n",
                    "title": "Vendor assessment"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-5774304",
                    "CSAFPID-5774305",
                    "CSAFPID-1394038",
                    "CSAFPID-1394039",
                    "CSAFPID-1394041",
                    "CSAFPID-5810402",
                    "CSAFPID-1439286",
                    "CSAFPID-1439292",
                    "CSAFPID-1439294",
                    "CSAFPID-1439300",
                    "CSAFPID-1439302",
                    "CSAFPID-1439304",
                    "CSAFPID-5794340",
                    "CSAFPID-5794343",
                    "CSAFPID-5794344",
                    "CSAFPID-5794346",
                    "CSAFPID-5794348",
                    "CSAFPID-5794351",
                    "CSAFPID-6175224",
                    "CSAFPID-6175225",
                    "CSAFPID-6450947",
                    "CSAFPID-6450948",
                    "CSAFPID-6450949",
                    "CSAFPID-6450950",
                    "CSAFPID-6450951",
                    "CSAFPID-6450952",
                    "CSAFPID-6450953",
                    "CSAFPID-6450954",
                    "CSAFPID-6450955",
                    "CSAFPID-6450956",
                    "CSAFPID-6450957",
                    "CSAFPID-6450958",
                    "CSAFPID-6450959",
                    "CSAFPID-6450960",
                    "CSAFPID-6450961",
                    "CSAFPID-6450962",
                    "CSAFPID-6450963",
                    "CSAFPID-6450964",
                    "CSAFPID-6450965",
                    "CSAFPID-6450966",
                    "CSAFPID-6450967",
                    "CSAFPID-6450968",
                    "CSAFPID-6450969",
                    "CSAFPID-165054",
                    "CSAFPID-8467863",
                    "CSAFPID-8467864",
                    "CSAFPID-1846999",
                    "CSAFPID-6213320",
                    "CSAFPID-6213321",
                    "CSAFPID-8878808",
                    "CSAFPID-9011234"
                ],
                "known_not_affected": [
                    "CSAFPID-1439334",
                    "CSAFPID-2467457",
                    "CSAFPID-5794339",
                    "CSAFPID-5794354"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/33xxx/CVE-2026-33929.json"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-33929"
                },
                {
                    "category": "external",
                    "summary": "Source - debian",
                    "url": "https://security-tracker.debian.org/tracker/CVE-2026-33929"
                },
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://api.github.com/advisories/GHSA-gcj8-76p4-g2fq"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-33929.json"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Maven%2FGHSA-gcj8-76p4-g2fq.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1687.json"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=10000"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/SUSE%2FSUSE-SU-2026:22088-1.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-33929.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=20000"
                },
                {
                    "category": "external",
                    "summary": "Source - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2895.json"
                },
                {
                    "category": "external",
                    "summary": "Source - ncscclear",
                    "url": "https://advisories.ncsc.nl/advisory?id=NCSC-2026-0312"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv; redhat",
                    "url": "https://github.com/apache/pdfbox/pull/427/changes"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv; redhat",
                    "url": "https://lists.apache.org/thread/op3lyx1ngzy4qycn06l6hljyf28ff0zs"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv; redhat",
                    "url": "https://lists.apache.org/thread/j8l07tgzy9dm8d8n0f3c45h7zg7t3ld6"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv; redhat",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33929"
                },
                {
                    "category": "external",
                    "summary": "Reference - github",
                    "url": "https://github.com/advisories/GHSA-gcj8-76p4-g2fq"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-33929"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-1687.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1687"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://www.ibm.com/support/pages/node/7273983"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202622088-1/"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://bugzilla.suse.com/1262046"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://www.suse.com/security/cve/CVE-2026-3392"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://www.suse.com/security/cve/CVE-2026-33929"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://repo.maven.apache.org/maven2"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33929.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2895.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2895"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://www.oracle.com/security-alerts/cspuaug2026.html#AppendixIFLX"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H",
                        "baseScore": 6.6,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-1394038",
                        "CSAFPID-1394039",
                        "CSAFPID-1394041",
                        "CSAFPID-1439286",
                        "CSAFPID-1439292",
                        "CSAFPID-1439294",
                        "CSAFPID-1439300",
                        "CSAFPID-1439302",
                        "CSAFPID-1439304",
                        "CSAFPID-165054",
                        "CSAFPID-1846999",
                        "CSAFPID-5774304",
                        "CSAFPID-5774305",
                        "CSAFPID-5794340",
                        "CSAFPID-5794343",
                        "CSAFPID-5794344",
                        "CSAFPID-5794346",
                        "CSAFPID-5794348",
                        "CSAFPID-5794351",
                        "CSAFPID-5810402",
                        "CSAFPID-6175224",
                        "CSAFPID-6175225",
                        "CSAFPID-6213320",
                        "CSAFPID-6213321",
                        "CSAFPID-6450947",
                        "CSAFPID-6450948",
                        "CSAFPID-6450949",
                        "CSAFPID-6450950",
                        "CSAFPID-6450951",
                        "CSAFPID-6450952",
                        "CSAFPID-6450953",
                        "CSAFPID-6450954",
                        "CSAFPID-6450955",
                        "CSAFPID-6450956",
                        "CSAFPID-6450957",
                        "CSAFPID-6450958",
                        "CSAFPID-6450959",
                        "CSAFPID-6450960",
                        "CSAFPID-6450961",
                        "CSAFPID-6450962",
                        "CSAFPID-6450963",
                        "CSAFPID-6450964",
                        "CSAFPID-6450965",
                        "CSAFPID-6450966",
                        "CSAFPID-6450967",
                        "CSAFPID-6450968",
                        "CSAFPID-6450969",
                        "CSAFPID-8467863",
                        "CSAFPID-8467864",
                        "CSAFPID-8878808",
                        "CSAFPID-9011234"
                    ]
                }
            ],
            "title": "CVE-2026-33929"
        }
    ]
}