pdfcpu v0.16.2
Hello!
We ship important security, stability, and PDF compatibility fixes with no breaking Go API changes.
The release requires Go 1.26 or later.
Upgrading is highly recommended!
Security
- Harden parsing and decoding against excessive work, circular references, malformed fonts, and invalid image parameters.
Enforce resource limits and prevent several malformed-input panics. - Reduce repeated validation of shared objects and memory allocations when parsing large certificate revocation lists.
- Correct AES-256 password preparation and owner authentication, encryption revision checks, and extraction permissions.
- Fix named and Identity crypt-filter handling, crypt-filter length units and validation, and encryption of strings
rewritten from object streams.
Fixes and improvements
- Preserve catalog data, inherited page boxes and resources, shared stamp resources, name-tree values, and named
destinations during processing. Correct compressed-object reference renumbering during merging. - Fix PDF whitespace, text and hexadecimal-string decoding, inline-image parsing, cross-reference handling, and
effective PDF version detection. - Improve form field inheritance, checkbox/radio handling, export ordering, JSON matching, list-box clearing, and
Unicode text-length checks. - Correct CMYK rendering, RGBA image import, Flate/TIFF predictor handling, and Crypt filter pipelines.
- Fix ToUnicode mappings, TrueType widths and style detection, and XMP date parsing.
- Complete required standard-font metrics for PDF 2.0 output and enforce required annotation appearances.
- Strengthen validation of images, graphics values, colour spaces, functions, destinations, PageLabels, and PDF 2.0
entries. Restore targeted multimedia compatibility and improve action reporting.
Compatibility
Existing Go API signatures remain unchanged; supporting packages receive additive exports. Strict validation now
rejects additional malformed inputs, while applicable relaxed compatibility is retained with notices. PDF 2.0 writes
report an error when required annotation appearances are missing; automatic appearance generation remains incomplete.
Encryption defaults are unchanged.
Thanks
Thanks everyone who opened issues.
Shoutout to @qoke and the IQ Hive team for providing a heavy load of critical fixes for this release.