Skip to content

SEC: Limit input size and element count for XMP metadata#3796

Merged
stefan6419846 merged 2 commits into
py-pdf:mainfrom
stefan6419846:xmp
May 22, 2026
Merged

SEC: Limit input size and element count for XMP metadata#3796
stefan6419846 merged 2 commits into
py-pdf:mainfrom
stefan6419846:xmp

Conversation

@stefan6419846
Copy link
Copy Markdown
Collaborator

No description provided.

@codecov
Copy link
Copy Markdown

codecov Bot commented May 22, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.68%. Comparing base (6b4bbcc) to head (a63bc70).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #3796   +/-   ##
=======================================
  Coverage   97.68%   97.68%           
=======================================
  Files          55       55           
  Lines       10353    10365   +12     
  Branches     1912     1913    +1     
=======================================
+ Hits        10113    10125   +12     
  Misses        134      134           
  Partials      106      106           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@stefan6419846 stefan6419846 merged commit 62191d5 into py-pdf:main May 22, 2026
18 checks passed
@stefan6419846 stefan6419846 deleted the xmp branch May 22, 2026 09:44
stefan6419846 added a commit that referenced this pull request May 22, 2026
## What's new

### Security (SEC)
- Limit input size and element count for XMP metadata (#3796) by @stefan6419846

### Robustness (ROB)
- Prevent cyclic parent hierarchies for inherited dictionaries (#3795) by @stefan6419846
- Deal with invalid first code in LZW decoder (#3794) by @stefan6419846

[Full Changelog](6.12.0...6.12.1)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant