CVE-2016-2175: Apache Pdfbox

High severity, CVSS 7.8. EPSS: 3.8% chance of exploitation in the next 30 days.

Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.

Affected products

  • Apache Pdfbox: version 1.8.0 only; version 1.8.1 only; version 1.8.2 only; version 1.8.3 only; version 1.8.4 only; version 1.8.5 only; …
  • Debian Debian Linux: version 8.0 only

Published 2016-06-01. Last modified 2026-06-17.