com.itextpdf:itextpdf vulnerabilities

Licenses: AGPL-3.0

Direct Vulnerabilities

Known vulnerabilities in the com.itextpdf:itextpdf package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Command Injection

[,5.5.13.3)
  • H
XML External Entity (XXE) Injection

[,5.5.12)

Package versions

36 VERSIONS IN TOTAL See all versions
versionpublisheddirect vulnerabilities
5.5.13.522 Jan, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.5.13.413 Jun, 2024
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.5.13.324 Feb, 2022
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.5.13.228 Aug, 2020
  • 0
    C
  • 1
    H
  • 0
    M
  • 0
    L
5.5.13.114 Jun, 2019
  • 0
    C
  • 1
    H
  • 0
    M
  • 0
    L
5.5.1326 Jan, 2018
  • 0
    C
  • 1
    H
  • 0
    M
  • 0
    L
5.5.1218 Aug, 2017
  • 0
    C
  • 1
    H
  • 0
    M
  • 0
    L
5.5.1120 Mar, 2017
  • 0
    C
  • 2
    H
  • 0
    M
  • 0
    L
5.5.107 Oct, 2016
  • 0
    C
  • 2
    H
  • 0
    M
  • 0
    L
5.5.916 Mar, 2016
  • 0
    C
  • 2
    H
  • 0
    M
  • 0
    L