Skip to content

Releases: itext/itextpdf

iText 5.5.13.5

23 Jan 12:28
5.5.13.5

Choose a tag to compare

Since the release of iText 5.5.13 the iText 5 product line has transitioned to be in maintenance mode, meaning it only receives security related releases. While iText 5 is now EOL, we want to make sure that our users who have developed their solutions using iText 5 can safely continue using it.

For this particular release, the Bouncy Castle cryptography libraries have been updated to their latest versions (Java to 1.83, .NET to 2.6.2) to address security vulnerabilities:

  • Java (BC Java 1.83): This version includes important security patches, such as the fix for CVE-2025-8916 (Allocation of Resources Without Limits or Throttling vulnerability)
  • .NET (BC C# 2.6.2): This version incorporates security fixes from previous releases. To review the detailed security history and related CVE information for the .NET library, you can check its NuGet page: BouncyCastle.Cryptography

iText 5.5.13.4

13 Jun 14:00
5.5.13.4

Choose a tag to compare

Security update of Bouncy Castle dependency to fix CVE-2024-29857.

While in the past we would ask our users to update this transitive dependency themselves, there has been a slight change in the Bouncy Castle API which warranted this release.

iText 5.5.13.3

25 Feb 09:32
5.5.13.3

Choose a tag to compare

Since the release of iText 5.5.13 the iText 5 product line has transitioned to be in maintenance mode, meaning it only receives security related releases. While iText 5 is now EOL, we want to make sure that our users who have developed their solutions using iText 5 can safely continue using it.

For this particular release, we’ve backported a security bug fix from iText 7.2.0 and 7.1.17 to resolve a vulnerability that allowed the use of GhostScript in an unpredictable manner. See CVE-2021-43113 for more information.

In addition, we have updated the Apache XML Security for Java (org.apache.santuario:xmlsec) dependency to version 1.5.8 from version 1.5.6.

The Bouncy Castle Crypto API for Java has also been updated to version 1.67 due to a flaw in the OpenBSDBCrypt.checkPassword() method present in 1.65 and 1.66. This was disclosed in CVE-2020-28052, see the link for more details.

Note that if you use some of the older Java versions (Java 1.5-1.8) you might need to update the bouncy castle dependency to a different specific distribution. On Maven it's org.bouncycastle.bcprov-jdk15to18.

From https://www.bouncycastle.org/latest_releases.html:

"Further Note (users of Oracle JVM 1.7 or earlier, users of "pre-Java 9" toolkits): As of 1.63 we have started including signed jars for "jdk15to18", if you run into issues with either signature validation in the JCE or the presence of the multi-release versions directory in the regular "jdk15on" jar files try the "jdk15to18" jars instead."

An example of an exception which might occur if the “standard" bouncy-castle distribution is used together with older Java versions:

java.security.NoSuchAlgorithmException: 1.2.840.113549.3.2 KeyGenerator not available.

iText 5.5.13.2

14 Sep 13:02
5.5.13.2

Choose a tag to compare

core

  • security update of bouncy castle dependency

iText 5.5.13.1

20 Jun 15:01
5.5.13.1

Choose a tag to compare

core

  • security fix for clearer signatures validation
  • security improvement around decompression bombs

iText 5.5.13

12 Feb 08:41

Choose a tag to compare

iText 5.5.13 is a maintenance release that rolls up 4 bugfixes for iText 5 Core from the past 5 months:

  • As of this release XFA Worker is no longer supported on .NET 2.0 - instead you need to use .NET 4.0.
  • Support has been added for License Key Library 3.0.1. Users on License Key Library 1.0.x should migrate to 3.0.1.
  • 3 bugfixes for iText 5 Core 5.5.13.
  • 1 bugfix for XFA Worker 5.5.13 (commercial add-on, not on GitHub).
    Please be informed that at the same time we release pdfXFA 1.0.3, an add-on for iText 7. All bugfixes for XFA Worker 5.5.13 were ported to pdfXFA 1.0.3.

No new functionality has been added since 5.5.11.

The full list of changes can be found in the changelogs and the release in our download hub for Java and .NET.

If you use Maven, then you can download iText from the Central Repository by adding one or more of the following XML snippets to your pom.xml:

<dependency>
  <groupId>com.itextpdf</groupId>
  <artifactId>itextpdf</artifactId>
  <version>${itext.version}</version>
</dependency>

<dependency>
  <groupId>com.itextpdf</groupId>
  <artifactId>itext-pdfa</artifactId>
  <version>${itext.version}</version>
</dependency>

<dependency>
  <groupId>com.itextpdf</groupId>
  <artifactId>itext-xtra</artifactId>
  <version>${itext.version}</version>
</dependency>

<dependency>
  <groupId>com.itextpdf.tool</groupId>
  <artifactId>xmlworker</artifactId>
  <version>${itext.version}</version>
</dependency>

Still questions about the release, don't hesitate to contact us.

iText 5.5.12

18 Aug 09:59

Choose a tag to compare

iText 5.5.12 is a maintenance release that rolls up 22 bugfixes for iText 5 Core from the past 5 months:

  • 22 bugfixes for iText 5 Core 5.5.12.
  • 6 bugfixes for XFAWorker 5.5.12 (Commercial add-on, not on GitHub).

No new functionality has been added since 5.5.11.

At the same time we also release pdfXFA 1.0.2, an add-on for iText 7. All bugfixes for XFAWorker 5.5.12 were ported to pdfXFA 1.0.2.

iText 5.5.11

20 Mar 10:48

Choose a tag to compare

iText 5.5.11 is a maintenance release that rolls up 28 bugfixes from the past 5 months. No new functionality has been added since 5.5.10.

iText 5.5.10

07 Oct 12:37

Choose a tag to compare

iText 5.5.9

16 Mar 10:54

Choose a tag to compare