Skip to content

Suppress PDFBox CVE#1308

Merged
labkey-tchad merged 2 commits intorelease25.11-SNAPSHOTfrom
25.11_fb_pdfboxUpdate
Mar 16, 2026
Merged

Suppress PDFBox CVE#1308
labkey-tchad merged 2 commits intorelease25.11-SNAPSHOTfrom
25.11_fb_pdfboxUpdate

Conversation

@labkey-tchad
Copy link
Member

Rationale

Suppress PDFBox CVE: https://nvd.nist.gov/vuln/detail/CVE-2026-23907
This seems like more of a PSA than an actual vulnerability. There's a path-traversal issue in some example code that isn't actually packaged in any of the flagged the jars.
There's no fix available yet, so I'm going to suppress the warning.

Related Pull Requests

  • N/A

Changes

  • Suppress PDFBox CVE

@labkey-tchad labkey-tchad requested review from a team and labkey-adam March 16, 2026 21:31
@labkey-tchad labkey-tchad merged commit ee0f491 into release25.11-SNAPSHOT Mar 16, 2026
10 checks passed
@labkey-tchad labkey-tchad deleted the 25.11_fb_pdfboxUpdate branch March 16, 2026 23:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants