PDF Deflate bombs

PDF Deflate bombs

Table of contents PDF Deflate bombs PDF streams in one minute Where the bomb lives Lazy parsing The more realistic iText trigger: PdfStamper Why the protection did not help Why this matters in real services Practical mitigations Takeaway PDF Deflate bombs While reviewing PDF processing flows in internal services, I started digging into known attack surfaces around PDF parsers and the internals of the format itself. PDFs turned out to be a surprisingly rich target: the format is built around indirect objects, streams, filters, decoding logic, fonts, images, metadata and many other structures that can become interesting from an attack perspective. ...

July 10, 2026 · 9 min