Skip to main content
Skip table of contents


iText dependencies:


  • CVE-2024-29857 - This CVE report describes a vulnerability discovered in the Java and .NET BouncyCastle dependencies for iText The version of iText 5, addresses this issue.


iText 5 targets Java 5 which means that we can not update org.apache.santuario:xmlsec version to 2.x.x or newer as it requires Java 8. If you are not using the class then you can avoid adding org.apache.santuario:xmlsec dependency into your project. Which means that you would not be affected by the related vulnerabilities, for example . If you are using class, for example for XFA signatures, then you can:

  • either use org.apache.santuario:xmlsec 1.5.8 as a dependency which is affected by the vulnerability specified above, but works on Java 5+;

  • CVE-2023-33201

It's safe for you to update your dependencies so that the bouncy castle transitive dependency is 1.74. For instance:



This CVE is not applicable to the product line iText 5.

This CVE is not applicable to the product line iText 5.

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.