Skip to content

veraPDF v1.30.3

Latest

Choose a tag to compare

@MaximPlusov MaximPlusov released this 09 Oct 11:07
· 36 commits to integration since this release

Version 1.30.3 (October 7, 2026)

Security

  • fixed excessive resource consumption caused by recursive validation of nested embedded files (GHSA-q2xp-cmwp-7cjh; commits 1 2)
  • fixed XML parser configuration that prevented security settings from being applied, restoring protection against XML external entity attacks (GHSA-5gvp-6g43-g47v; commit)
  • fixed potential excessive memory allocation when parsing CFF font INDEX structures with a corrupted data size or offset size (GHSA-fg6c-v27x-ffpx; commit)
  • fixed potential stack overflow and excessive resource consumption caused by deeply nested procedures in Type 4 functions (GHSA-3pqj-5xfj-xrh9; commit)

Validation

  • (PDF/UA-2, WTPDF-1) added a rule requiring PDF version 2.0 (commit)
  • (PDF/UA-2, WTPDF-1) improved descriptions for rules 8.2.5.20-1 and 8.9.2.3-1 (commit)
  • (PDF/UA-2, WTPDF-1) corrected the error message for rule 8.2.5.20-2 (commits 1 2)
  • (PDF/UA-2, WTPDF-1) fixed an infinite loop when determining whether an annotation is an Artifact in a document with circular structure-element parent references (commit)
  • (PDF/UA-1) restored the PDF 1.7 algorithm for determining table header scope in place of the PDF 2.0 algorithm (commit)
  • (PDF/A-4) fixed detection of undefined resources when a page has no Resources entry (commits 1 2)
  • (PDF/A-4) fixed handling of Resources dictionaries in individual Type3 CharProc streams (commit)

Core library

  • fixed JAXB compatibility issues caused by reflective modification of final fields (commit)
  • added JavaScriptEvaluator.clearScripts() to clear the current thread's cached scripts and allow associated Rhino classloaders to be reclaimed (commit)
  • added support for cancelling validation through thread interruption (commit)
  • fixed cleanup of temporary log files (commit)

PDF Parser

  • fixed parsing of CFF fonts when FontMatrix immediately follows ROS in the Top DICT (commit)
  • fixed decryption of documents with R=4 and V=4 when the encryption dictionary has no Length entry (commit)
  • fixed AES-256 revision 6 password hashing that could incorrectly reject valid passwords (commit)
  • fixed cleanup of object streams during saveAs (commit)
  • added configuration of the temporary-file directory and in-memory buffer size (commit)
  • added an optional size limit for streams written to temporary files (commit)
  • added an optional limit on the number of indirect objects in a document (commit)
  • added methods to clear and limit the dynamic PDF-name cache (commit)
  • removed incorrect log messages about missing TrueType cmap tables and invalid use of ICCBased color spaces (commits 1 2 3)
  • added logging for invalid hexadecimal strings in content streams (commit)