Since the release of iText 5.5.13 the iText 5 product line has transitioned to be in maintenance mode, meaning it only receives security related releases. While iText 5 is now EOL, we want to make sure that our users who have developed their solutions using iText 5 can safely continue using it.
This is an iText 5 security release which backports the single-layered decompression bomb scenario fix from iText Core 9.7.0. See Release iText Core 9.7.0 | Security and Stability for more details.
In addition, the Java Bouncy Castle cryptography libraries were updated to 1.84 to address CVE-2026-5588.
Downloads