PDFreactor 12 Hotfix Release 12.7.1 now available

A release for PDFreactor 12 is now available.

The following issues were fixed:
  • Merging documents with a very large amount of bookmarks can cause conversions to terminate with exceptions. (#10054)
  • Inset box-shadows at high -ro-rasterization-supersampling values are rendered incorrectly. (#9959, #9960)
  • Using asset packages in combination with merge mode append fails. (#9983)
  • Some code snippets in the documentation are incorrect. (#9702)
The following CVEs in 3rd party dependencies were mitigated:
  • Mitigated CVEs in packaged Java runtime. (CVE-2026-41254, CVE-2026-46917, CVE-2026-46968, CVE-2026-47010, CVE-2026-47021, CVE-2026-47027, CVE-2026-47059, CVE-2026-47063, CVE-2026-60147)
  • CVE-2025-66453
  • CVE-2026-19032
  • CVE-2026-54078 (#10033)
  • CVE-2026-54079 (#10034)
  • CVE-2026-54080
  • CVE-2026-54081
  • CVE-2026-54082
  • CVE-2026-54512
  • CVE-2026-54513
  • CVE-2026-54514
  • CVE-2026-54515
  • CVE-2026-54518
  • CVE-2026-59888
  • CVE-2026-64607
  • CVE-2026-68497
  • PDFreactor Web Service
    • CVE-2026-6790
    • CVE-2026-8384
    • CVE-2026-10050
    • CVE-2026-10051
    • CVE-2026-54225
    • CVE-2026-54516
    • CVE-2026-54517
    • CVE-2026-57819
    • CVE-2026-59889
    • CVE-2026-64958
    • CVE-2026-65432
The following dependencies were updated:
  • Packaged Java runtime Eclipse Temurin 21.0.11 to 21.0.12
  • com.fasterxml.jackson.* 2.19.0 to 2.22.1
  • org.apache.httpcomponents.client5.* 5.5 to 5.6.3
  • org.verapdf.* 1.28.1 to 1.30.2
  • PDFreactor Web Service
    • com.fasterxml.jackson.* 2.21.1 to 2.22.1
    • org.apache.cxf.* 4.1.7 to 4.1.8
    • org.eclipse.jetty.* 12.0.33 to 12.0.38

For a full list of changes and corrections see the changelog.

Important release notes und upgrading information can be found in the readme.

The PDFreactor 12 installation packages are available for download in the download area.