{"api_version":"v1","generated_at":"2026-10-06T02:05:00+00:00","product":{"cve_count":6,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-apache-software-foundation-apache-pdfbox-972ab40be578","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Apache PDFBox","next_cursor":null,"observations":[{"affected":"Apache PDFBox < 2.0.24","affected_versions_present":true,"cve_id":"CVE-2021-31812","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-31812","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T23:10:30.239Z","patch_url":"https://www.oracle.com/security-alerts/cpuoct2021.html","primary_source":"","published":"2021-06-12T09:45:11.000Z"},{"affected":"Apache PDFBox < 2.0.24","affected_versions_present":true,"cve_id":"CVE-2021-31811","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-31811","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T23:10:30.183Z","patch_url":"https://www.oracle.com/security-alerts/cpujan2022.html","primary_source":"","published":"2021-06-12T09:45:11.000Z"},{"affected":"Apache PDFBox \u2264 2.0.22","affected_versions_present":true,"cve_id":"CVE-2021-27906","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-27906","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-02-13T16:27:57.655Z","patch_url":"https://www.oracle.com//security-alerts/cpujul2021.html","primary_source":"","published":"2021-03-19T16:05:21.000Z"},{"affected":"Apache PDFBox \u2264 2.0.22","affected_versions_present":true,"cve_id":"CVE-2021-27807","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-27807","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-02-13T16:27:57.032Z","patch_url":"https://www.oracle.com//security-alerts/cpujul2021.html","primary_source":"","published":"2021-03-19T16:05:20.000Z"},{"affected":"1.8.0 to 1.8.15; 2.0.0RC1 to 2.0.11","affected_versions_present":true,"cve_id":"CVE-2018-11797","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-11797","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-16T16:33:51.092Z","patch_url":"https://www.oracle.com/security-alerts/cpuapr2020.html","primary_source":"","published":"2018-10-05T20:00:00.000Z"},{"affected":"1.8.0 to 1.8.14; 2.0.0RC1 to 2.0.10","affected_versions_present":true,"cve_id":"CVE-2018-8036","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-8036","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-16T18:28:45.288Z","patch_url":"","primary_source":"","published":"2018-07-03T20:00:00.000Z"}],"source_generated_at":"2026-10-05T06:20:29.126Z","vendor":"Apache Software Foundation"}}
