v0.16.1
Security and stability update with no public API changes. Requires Go 1.26 or later.
This release fixes a denial-of-service vulnerability in grayscale and Indexed image rendering, including CalRGB palette handling. Processing a crafted PDF could cause an index-out-of-range panic and terminate the calling process if the panic was not recovered.
Versions v0.16.0 and earlier are affected. Applications extracting or rendering images from untrusted PDFs should upgrade to v0.16.1. See GHSA-6524-w46v-6399.
Improvements:
- Harden PDF parsing, image processing, JSON input handling, and signature-data parsing.
- Prevent panics when rendering grayscale and Indexed images, including palette bounds and Decode mapping checks.
- Strengthen external-link checks and reporting of problematic links; redact URL passwords in reports and CLI output.
- Improve structural validation of embedded files, 3D annotations, and multimedia dictionaries.
- Report JavaScript and supported media presence during validation without executing content or displaying script code.
- Report invalid zero-offset xref entries as skipped in relaxed validation and reject them in strict mode (#612).
- Fix strict validation of PDF dates ending in
Z(#1493). - Update the TIFF dependency to v1.0.7.