GHSA-2h3j-m7gr-25xj · Severity: medium · Ecosystem: maven — Excessive Iteration Denial of Service in Apache PDFBox
A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
Conclusion & alert: CVE-2021-27807 is rated Moderate Risk (45.5/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.54%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-09-13 | 0.44% | 0.54% | +0.10% |
| 2 | 2025-08-31 | 0.33% | 0.44% | +0.11% |
| 3 | 2025-07-02 | — | 0.33% | — |
Full EPSS history (19 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.5 | 3.1 | MEDIUM |
|
1.8 | 3.6 | [email protected] |
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
GHSA-2h3j-m7gr-25xj · Severity: medium · Ecosystem: maven — Excessive Iteration Denial of Service in Apache PDFBox
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2021-27807 unimportant priority: Debian including 2 source packages (libpdfbox-java, libpdfbox2-java), 10 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 10. | https://security-tracker.debian.org/tracker/CVE-2021-27807 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2021-27807 |
suse
|
high | CVE-2021-27807 severity important: SUSE including 7 source package names (apache-pdfbox, apache-pdfbox-2.0.23-1.3, …), 37 product×package rows across 34 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 6, … (34 product lines)): Fixed 23, Known Not Affected 14. | https://www.suse.com/security/cve/CVE-2021-27807/ |
ubuntu
|
medium | CVE-2021-27807 medium priority: Ubuntu including 2 source packages (libpdfbox-java, libpdfbox2-java), 32 status rows across 16 suites (bionic, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): ignored 16, needs-triage 11, DNE 3, needed 2. | https://ubuntu.com/security/CVE-2021-27807 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| apache | pdfbox | >= 2.0.0, <= 2.0.22 | cpe:2.3:a:apache:pdfbox:*:*:*:*:*:*:*:* |
| fedoraproject | fedora | 32 | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* |
| fedoraproject | fedora | 33 | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* |
| fedoraproject | fedora | 34 | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* |
| oracle | banking_trade_finance_process_management | 14.2.0 | cpe:2.3:a:oracle:banking_trade_finance_process_management:14.2.0:*:*:*:*:*:*:* |
| oracle | banking_trade_finance_process_management | 14.3.0 | cpe:2.3:a:oracle:banking_trade_finance_process_management:14.3.0:*:*:*:*:*:*:* |
| oracle | banking_trade_finance_process_management | 14.5.0 | cpe:2.3:a:oracle:banking_trade_finance_process_management:14.5.0:*:*:*:*:*:*:* |
| oracle | banking_treasury_management | 14.5 | cpe:2.3:a:oracle:banking_treasury_management:14.5:*:*:*:*:*:*:* |
| oracle | banking_virtual_account_management | 14.2.0 | cpe:2.3:a:oracle:banking_virtual_account_management:14.2.0:*:*:*:*:*:*:* |
| oracle | banking_virtual_account_management | 14.3.0 | cpe:2.3:a:oracle:banking_virtual_account_management:14.3.0:*:*:*:*:*:*:* |
| oracle | banking_virtual_account_management | 14.5.0 | cpe:2.3:a:oracle:banking_virtual_account_management:14.5.0:*:*:*:*:*:*:* |
| oracle | communications_session_report_manager | >= 8.0.0, <= 8.2.4.0 | cpe:2.3:a:oracle:communications_session_report_manager:*:*:*:*:*:*:*:* |
| oracle | flexcube_universal_banking | >= 14.0.0, <= 14.3.0 | cpe:2.3:a:oracle:flexcube_universal_banking:*:*:*:*:*:*:*:* |
| oracle | flexcube_universal_banking | 14.5.0 | cpe:2.3:a:oracle:flexcube_universal_banking:14.5.0:*:*:*:*:*:*:* |
| oracle | hyperion_financial_reporting | 11.1.2.4 | cpe:2.3:a:oracle:hyperion_financial_reporting:11.1.2.4:*:*:*:*:*:*:* |
| oracle | hyperion_financial_reporting | 11.2.6.0 | cpe:2.3:a:oracle:hyperion_financial_reporting:11.2.6.0:*:*:*:*:*:*:* |
| oracle | hyperion_infrastructure_technology | < 11.2.8.0 | cpe:2.3:a:oracle:hyperion_infrastructure_technology:*:*:*:*:*:*:*:* |
| oracle | outside_in_technology | 8.5.5 | cpe:2.3:a:oracle:outside_in_technology:8.5.5:*:*:*:*:*:*:* |
| oracle | primavera_unifier | >= 17.7, <= 17.12 | cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:* |
| oracle | primavera_unifier | 18.8 | cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:* |
| oracle | primavera_unifier | 19.12 | cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:* |
| oracle | primavera_unifier | 20.12 | cpe:2.3:a:oracle:primavera_unifier:20.12:*:*:*:*:*:*:* |
| oracle | retail_customer_management_and_segmentation_foundation | 19.0 | cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:19.0:*:*:*:*:*:*:* |
| oracle | retail_xstore_point_of_service | 16.0.6 | cpe:2.3:a:oracle:retail_xstore_point_of_service:16.0.6:*:*:*:*:*:*:* |
| oracle | retail_xstore_point_of_service | 17.0.4 | cpe:2.3:a:oracle:retail_xstore_point_of_service:17.0.4:*:*:*:*:*:*:* |
| oracle | retail_xstore_point_of_service | 18.0.3 | cpe:2.3:a:oracle:retail_xstore_point_of_service:18.0.3:*:*:*:*:*:*:* |
| oracle | retail_xstore_point_of_service | 19.0.2 | cpe:2.3:a:oracle:retail_xstore_point_of_service:19.0.2:*:*:*:*:*:*:* |
| oracle | retail_xstore_point_of_service | 20.0.1 | cpe:2.3:a:oracle:retail_xstore_point_of_service:20.0.1:*:*:*:*:*:*:* |
| oracle | webcenter_sites | 12.2.1.3.0 | cpe:2.3:a:oracle:webcenter_sites:12.2.1.3.0:*:*:*:*:*:*:* |
| oracle | webcenter_sites | 12.2.1.4.0 | cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:* |
| oracle | communications_messaging_server | 8.1 | cpe:2.3:o:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:* |