From d547eccd2bd5131f2e9457528386f9418074bea0 Mon Sep 17 00:00:00 2001 From: Susan Hert Date: Wed, 22 Apr 2026 14:48:42 -0700 Subject: [PATCH] Suppress CVEs for PDFbox that does not affect us (#1349) --- dependencyCheckSuppression.xml | 45 ++++++++++++++++++++++++++++------ gradle.properties | 2 +- 2 files changed, 38 insertions(+), 9 deletions(-) diff --git a/dependencyCheckSuppression.xml b/dependencyCheckSuppression.xml index d610e97a2b..7a3b3b8e8c 100644 --- a/dependencyCheckSuppression.xml +++ b/dependencyCheckSuppression.xml @@ -229,32 +229,60 @@ --> + file name: pdfbox-3.0.7.jar + ]]> ^pkg:maven/org\.apache\.pdfbox/pdfbox@.*$ CVE-2026-23907 + file name: pdfbox-debugger-3.0.7.jar + ]]> ^pkg:maven/org\.apache\.pdfbox/pdfbox-debugger@.*$ CVE-2026-23907 + file name: pdfbox-io-3.0.7.jar + ]]> ^pkg:maven/org\.apache\.pdfbox/pdfbox-io@.*$ CVE-2026-23907 + file name: pdfbox-tools-3.0.7.jar + ]]> ^pkg:maven/org\.apache\.pdfbox/pdfbox-tools@.*$ CVE-2026-23907 + + + ^pkg:maven/org\.apache\.pdfbox/pdfbox@.*$ + CVE-2026-33929 + + + + ^pkg:maven/org\.apache\.pdfbox/pdfbox-debugger@.*$ + CVE-2026-33929 + + + + ^pkg:maven/org\.apache\.pdfbox/pdfbox-io@.*$ + CVE-2026-33929 + + + + ^pkg:maven/org\.apache\.pdfbox/pdfbox-tools@.*$ + CVE-2026-33929 +