unstructured
fix(security): bound quadratic array-stream decoding in is_pdf_too_complex (SEC-146)
#4437
Merged

fix(security): bound quadratic array-stream decoding in is_pdf_too_complex (SEC-146) #4437

aadland6
aadland6 fix(security): bound quadratic array-stream decoding in is_pdf_too_co…
1c5c953b
aadland6 fix(security): harden is_pdf_too_complex bounds after peer review (SE…
af7617da
aadland6 fix(security): close document-budget bypass and add entry cap (SEC-146)
85805b32
cubic-dev-ai
cubic-dev-ai commented on 2026-08-14
aadland6 fix(security): fail closed on pypdf decode-limit; drop dead test code…
3710f316
cubic-dev-ai
cubic-dev-ai commented on 2026-08-14
aadland6 fix(security): charge non-stream array entries to the document budget…
1029ddbd
cubic-dev-ai
cubic-dev-ai commented on 2026-08-14
aadland6 docs(pdf): trim verbose comments and CHANGELOG for is_pdf_too_complex…
9ecde0f0
cubic-dev-ai
cubic-dev-ai commented on 2026-08-14
aadland6 chore(release): finalize version 0.26.1 (drop -dev0) (SEC-146)
4dd9d50b
cubic-dev-ai
cubic-dev-ai commented on 2026-08-14
badGarnet
aadland6 fix(security): inspect small files by default; per-item decode errors…
c8b495b0
cubic-dev-ai
cubic-dev-ai commented on 2026-08-14
upwind-code-us
upwind-code-us
badGarnet
badGarnet approved these changes on 2026-08-14
aadland6
aadland6 aadland6 merged 44f9d747 into main 5 days ago
aadland6 aadland6 deleted the matthew/sec-146-quadratic-memorycpu-in-is_pdf_too_complex-array-stream branch 5 days ago

Login to write a write a comment.

Login via GitHub

Assignees
No one assigned
Labels
Milestone