Skip to content

BUG: Correctly verify AES padding during decryption#3699

Merged
stefan6419846 merged 3 commits intopy-pdf:mainfrom
stefan6419846:padding
Mar 26, 2026
Merged

BUG: Correctly verify AES padding during decryption#3699
stefan6419846 merged 3 commits intopy-pdf:mainfrom
stefan6419846:padding

Conversation

@stefan6419846
Copy link
Copy Markdown
Collaborator

Additionally removes the handling for incorrectly padded inputs - these files are most likely not valid and it would be unexpected to let them pass without further notice.

Additionally removes the handling for incorrectly padded inputs - these
files are most likely not valid and it would be unexpected to let them
pass without further notice.
@codecov
Copy link
Copy Markdown

codecov bot commented Mar 26, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.43%. Comparing base (4d8ebce) to head (0dcfc30).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #3699      +/-   ##
==========================================
- Coverage   97.43%   97.43%   -0.01%     
==========================================
  Files          55       55              
  Lines       10009    10005       -4     
  Branches     1839     1837       -2     
==========================================
- Hits         9752     9748       -4     
  Misses        149      149              
  Partials      108      108              

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@stefan6419846 stefan6419846 merged commit 018a52e into py-pdf:main Mar 26, 2026
31 of 32 checks passed
@stefan6419846 stefan6419846 deleted the padding branch March 26, 2026 13:18
stefan6419846 added a commit that referenced this pull request Apr 10, 2026
## What's new

### Security (SEC)
- Disallow custom XML entity declarations for XMP metadata (#3724) by @stefan6419846

### New Features (ENH)
- Skip MD5 key derivation for AES-256 encrypted PDFs (#3694) by @Ygnas

### Bug Fixes (BUG)
- Use remove_orphans in compress_identical_objects (#3310) by @j-t-1
- Fix PdfReadError when xref table contains comments before trailer (#3710) by @rassie
- Correctly verify AES padding during decryption (#3699) by @stefan6419846
- Fix stale object cache from non-authoritative object streams (#3698) by @astahlman
- Fix extract_links pairing when annotations include non-links (#3687) by @ReinerBRO

### Documentation (DOC)
- Add AI policy (#3717) by @stefan6419846

[Full Changelog](6.9.2...6.10.0)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant