v1.14.2

Netw0rkNoob/VulnClawv1.14.2Aug 13, 2026by abimaelmartell

AI Summary

This release hardens the PDF parser against malformed or malicious files by introducing strict resource bounds to prevent unbounded CPU or memory usage. It also improves extraction quality for nested forms and handles small-caps text correctly.

Key Highlights

  • Hardened parsing to prevent unbounded CPU or memory usage in crafted PDFs
  • Implemented resource bounds for Form XObject expansion, CID ranges, and content-stream decode
  • Enhanced Form XObject text handling by tracking the text line matrix and spacing operators
  • Fixed small-caps runs merging to prevent them from being read as table columns

New Features

  • Resource bounds enforcement for various PDF operators
  • Improved Form XObject text extraction and spacing handling
  • Small-caps text run merging

Full Release Notes

## Packages

All packages were built from source checkpoint [`4bee4f9`](https://github.com/firecrawl/pdf-inspector/commit/4bee4f993ba28bd6a3334fa55e699b318663fba3).

- [Rust crate `pdf-inspector` 1.14.2](https://crates.io/crates/pdf-inspector/1.14.2) — `cargo add pdf-inspector@1.14.2`
- [Python `pdf-inspector` 1.14.2](https://pypi.org/project/pdf-inspector/1.14.2/) — `pip install pdf-inspector==1.14.2`
- [Node `@firecrawl/pdf-inspector` 1.14.2](https://www.npmjs.com/package/@firecrawl/pdf-inspector/v/1.14.2) — `npm install @firecrawl/pdf-inspector@1.14.2`
- [WebAssembly `@firecrawl/pdf-inspector-wasm` 1.14.2](https://www.npmjs.com/package/@firecrawl/pdf-inspector-wasm/v/1.14.2) — `npm install @firecrawl/pdf-inspector-wasm@1.14.2`

<details>
<summary>Node platform packages</summary>

- [Linux x64 glibc](https://www.npmjs.com/package/@firecrawl/pdf-inspector-linux-x64-gnu/v/1.14.2)
- [Linux x64 musl](https://www.npmjs.com/package/@firecrawl/pdf-inspector-linux-x64-musl/v/1.14.2)
- [Linux ARM64 glibc](https://www.npmjs.com/package/@firecrawl/pdf-inspector-linux-arm64-gnu/v/1.14.2)
- [Linux ARM64 musl](https://www.npmjs.com/package/@firecrawl/pdf-inspector-linux-arm64-musl/v/1.14.2)
- [macOS ARM64](https://www.npmjs.com/package/@firecrawl/pdf-inspector-darwin-arm64/v/1.14.2)
- [Windows x64 MSVC](https://www.npmjs.com/package/@firecrawl/pdf-inspector-win32-x64-msvc/v/1.14.2)

</details>

## Highlights

- Caps Form XObject expansion, CID `/W` ranges, Encoding/ToUnicode CMaps, content-stream decode, detector `Tj`/`TJ` lookback, and disjoint-rect clustering so crafted PDFs cannot force unbounded CPU or memory (#370, #372, #373, #375, #379, #380, #381).
- Form XObjects now track the text line matrix and honor `T*` / `TL` / `'` / `"` / `Tc` / `Tw`, so nested form text keeps the right spacing (#369).
- Small-caps runs merge instead of being read as extra table columns (#371).

## Changes since 1.14.1

Source: [`f4aab3b...4bee4f9`](https://github.com/firecrawl/pdf-inspector/compare/f4aab3b...4bee4f9)

### Resource bounds
- Bound Form XObject expansion per page (#370)
- Bound CID `/W` range expansion (#372)
- Cap content-stream decode before allocating operators (#373)
- Bound Encoding CMap `cidrange` expansion (#375)
- Bound ToUnicode `bfrange` expansion during subset remap (#379)
- Bound detector `Tj`/`TJ` operand lookback to the previous operator (#380)
- Bound disjoint-rect table clustering so overlap tests stay subquadratic (#381)

### Extraction quality
- Track the text line matrix and handle `T*` / `TL` / `'` / `"` / `Tc` / `Tw` in Form XObjects (#369)
- Merge small-caps runs so they stop reading as table columns (#371)