CVE-2021-27906
MediumAdvisory
Published 13 May 2021In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.5
- base score, highest
- EPSS
- 0.033
- 88th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 7
- of 17,781 indexed, latest versions
- Container images
- 6
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Uncontrolled Memory Allocation in Apache PDFBox
Carried by container images the latest versions of 7 of 17,781 indexed charts deploy, on 6 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| pdfboxmaven | 2.0.6, 2.0.13, 2.0.16, 2.0.19+1 more | 2.0.23 | 6 |
- OSV records
- GHSA-6vqp-h455-42mr
Charts affected
7 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| solrpreferred-aiVerified publisher | 3.2.0 | 1 of 3See more | 6,048 |
| zammaddevplayer0Verified publisher | 4.0.5 | 1 of 4See more | 6,110 |
| openkmgeek-cookbookVerified publisher | 4.2.0 | 1 of 1See more | 27,949 |
| teedygeek-cookbookVerified publisher | 6.2.0 | 1 of 1See more | 26,944 |
| ubooquityhalkeye | 0.1.1 | 1 of 1See more | 4,303 |
| atlassian-confluencesomeblackmagic | 3.4.1 | 1 of 1See more | 13,605 |
| ubooquityvhdirkVerified publisher | 0.1.3 | 1 of 1See more | 4,303 |
Container images carrying it
6 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| linuxserver/ | 9932d6759112 | pdfbox | 2.0.23 | 2 |
| atlassian/ | 3b9222ab32ef | pdfbox | 2.0.23 | 1 |
| library/ | d124efd81fbb | pdfbox | 2.0.23 | 1 |
| openkm/ | 3bc465a7461b | pdfbox | 2.0.23 | 1 |
| sismics/ | f4b0ef019cf1 | pdfbox | 2.0.23 | 1 |
| zammad/ | 8274d75a51fc | pdfbox | 2.0.23 | 1 |