PDFreactor 12 Hotfix Release 12.7.2 now available
A release for PDFreactor 12 is now available.
The following issues were fixed:
- PDF conformance modes that require specific color spaces erroneously reject spot/separation colors. (#10101)
- Some WebP images can have a green tint. (#9536)
- Misc. security fixes. (#10201, #10202, #10167, #10192)
- Some unused 3rd party classes can cause false positives in static code analysis tools. (#10114)
The following functionalities were deprecated:
- PDFreactor Web Service
- The SOAP API (
/service/soap) is deprecated and will be removed in the next minor release of PDFreactor. (#10203)
- The SOAP API (
The following CVEs in 3rd party dependencies were mitigated:
- Mitigated CVEs in packaged Java runtime. (CVE-2026-60589, CVE-2026-61308, CVE-2026-70907)
- CVE-2025-66453
- CVE-2026-19032
- CVE-2026-33929
- CVE-2026-66142
- CVE-2026-66143
- CVE-2026-66144
- CVE-2026-68497
- CVE-2026-68498
- CVE-2026-71290
- CVE-2026-83557
- CVE-2026-89407
- CVE-2026-89425
- CVE-2026-91776
- CVE-2026-91777
- CVE-2026-91863
- CVE-2026-91864
- CVE-2026-91865
- CVE-2026-91866
- CVE-2026-91867
- CVE-2026-102495
- CVE-2026-102496
The following dependencies were updated:
- Packaged Java runtime Eclipse Temurin 21.0.12 to 21.0.12.1
- com.twelvemonkeys.imageio.* 3.13.1 to 3.15.3
- com.fasterxml.jackson.* 2.22.1 to 2.22.3
- org.apache.pdfbox.* 3.0.7 to 3.0.8
- org.apache.httpcomponents.client5.* 5.6.3 to 5.6.4
- PDFreactor Web Service
- org.slf4j:slf4j-api 2.0.18 to 2.0.20
- org.apache.ws.xmlschema.* 2.3.2 to 2.3.
- org.apache.neethi.* 3.2.2 to 3.2.4
For a full list of changes and corrections see the changelog.
Important release notes und upgrading information can be found in the readme.
The PDFreactor 12 installation packages are available for download in the download area.


