iText

Release iText Core 9.7.1

Release date:

This is a Java-only patch release for iText Core that addresses a security vulnerability in the Jackson JSON dependency. All users on 9.7.0 are encouraged to upgrade to resolve the issues described in CVE-2026-54515.

In addition, version 4.2.8 of the Java License Key Library was released to fix the CVE-2026-54399 and CVE-2026-54428 issues stemming from the httpclient used for license validation.

Downloads


GitHub

Maven

NuGet

Artifactory

iText Core – 9.7.1 (Java)


link

link

N/A

link


License Key Library (Java)




licensing-root - link

licensing-base - link

licensing-remote - link

Changelog

Improvements

  • DEVSIX-10085 - Bump Jackson dependency to 2.22.1 to fix CVE-2026-54515

  • DEVSIX-10095 - Fix CVE-2026-54399 and CVE-2026-54428 from httpclient for licensing-remote