SetaPDF 2.53 and FPDI PDF-Parser 2.1.8 released2026-09-16
After introducing plausibility checks for cross-reference streams in our last releases, we were confronted with reality: we discovered that various well-known PDF generators produce faulty cross-reference streams containing unnecessary content.
These releases bring back compatiblity for such PDF documents in both SetaPDF and the FPDI PDF-Parser add-on! Please upgrade as soon as possible if you process foreign PDF documents!
While we dropped PHP 7.1 support in SetaPDF in this release we verified compatibility with the PHP 8.6 Beta 3 release for both SetaPDF and the FPDI PDF-Parser add-on.
Check the release notes of the components below.
Log in to download the latest version of the related packages!
Version 2.1.8
Release date: 2026-09-14
| Filename | Download | Composer
[ ? Use following minimal composer.json file to install a package through Composer. |
Information |
|---|
FPDI PDF-Parser
Tweak
- Optimized plausibility checks for cross-reference stream length (bring back support for some faulty cross-reference streams).
- Verified compatibility with PHP 8.6.
Version 2.53.0.2374
Release date: 2026-09-16
| Filename | Download | Composer
[ ? Use following minimal composer.json file to install a package through Composer. |
Information |
|---|
SetaPDF-Core Component
Bugfix
- Clean up generated tmp files in
SecHandler\PublicKey. - Fixed
TypeErrorinDocument\Action\Action::addNext()which was triggered when called on an action without a "Next"-value. - Fixed setting of value in
TextAnnotation::setStateModel()on annotations with an already defined StateModel. - Fixed "Undefined array key" error in
CrossReferenceTable::getGenerationNumberByObjectId(). - Use only information from the last trailer dictionary when parsing incremental updates.
- Write correct cross-reference if only the trailer was updated.
Tweak
- Added various checks for a valid key-length in
SecHandler\SecHandlerandSecHandler\AbstractHandlerclass. - Streamlined all setter methods in
Page\Annotationclasses to use the fluent-interface. - Improved documentation of various methods return types.
- Ensured compatibility with PHP 8.6.
- Dropped support for PHP 7.1.
- Optimized plausibility checks for cross-reference stream length (bring back support for some faulty cross-reference streams).
Version 2.53.0.2374
Release date: 2026-09-16
| Filename | Download | Composer
[ ? Use following minimal composer.json file to install a package through Composer. |
Information |
|---|
SetaPDF-Extractor Component
Bugfix
- Fixed return type for
TextItem::getNo()fromPlainStrategy(was documented as string but was an integer - it's now a string).
SetaPDF-Core Component
Bugfix
- Clean up generated tmp files in
SecHandler\PublicKey. - Fixed
TypeErrorinDocument\Action\Action::addNext()which was triggered when called on an action without a "Next"-value. - Fixed setting of value in
TextAnnotation::setStateModel()on annotations with an already defined StateModel. - Fixed "Undefined array key" error in
CrossReferenceTable::getGenerationNumberByObjectId(). - Use only information from the last trailer dictionary when parsing incremental updates.
- Write correct cross-reference if only the trailer was updated.
Tweak
- Added various checks for a valid key-length in
SecHandler\SecHandlerandSecHandler\AbstractHandlerclass. - Streamlined all setter methods in
Page\Annotationclasses to use the fluent-interface. - Improved documentation of various methods return types.
- Ensured compatibility with PHP 8.6.
- Dropped support for PHP 7.1.
- Optimized plausibility checks for cross-reference stream length (bring back support for some faulty cross-reference streams).
Version 2.53.0.2374
Release date: 2026-09-16
| Filename | Download | Composer
[ ? Use following minimal composer.json file to install a package through Composer. |
Information |
|---|
SetaPDF-FormFiller Full Component
Bugfix
- Only updated the readOnly attribute in
Xfa::setReadOnly()if it was changed. - Fixed filling of list fields in XFA forms with multiple values while using another encoding than UTF-8.
SetaPDF-Core Component
Bugfix
- Clean up generated tmp files in
SecHandler\PublicKey. - Fixed
TypeErrorinDocument\Action\Action::addNext()which was triggered when called on an action without a "Next"-value. - Fixed setting of value in
TextAnnotation::setStateModel()on annotations with an already defined StateModel. - Fixed "Undefined array key" error in
CrossReferenceTable::getGenerationNumberByObjectId(). - Use only information from the last trailer dictionary when parsing incremental updates.
- Write correct cross-reference if only the trailer was updated.
Tweak
- Added various checks for a valid key-length in
SecHandler\SecHandlerandSecHandler\AbstractHandlerclass. - Streamlined all setter methods in
Page\Annotationclasses to use the fluent-interface. - Improved documentation of various methods return types.
- Ensured compatibility with PHP 8.6.
- Dropped support for PHP 7.1.
- Optimized plausibility checks for cross-reference stream length (bring back support for some faulty cross-reference streams).
Version 2.53.0.2374
Release date: 2026-09-16
| Filename | Download | Composer
[ ? Use following minimal composer.json file to install a package through Composer. |
Information |
|---|
SetaPDF-FormFiller Lite Component
Bugfix
- Only updated the readOnly attribute in
Xfa::setReadOnly()if it was changed. - Fixed filling of list fields in XFA forms with multiple values while using another encoding than UTF-8.
SetaPDF-Core Component
Bugfix
- Clean up generated tmp files in
SecHandler\PublicKey. - Fixed
TypeErrorinDocument\Action\Action::addNext()which was triggered when called on an action without a "Next"-value. - Fixed setting of value in
TextAnnotation::setStateModel()on annotations with an already defined StateModel. - Fixed "Undefined array key" error in
CrossReferenceTable::getGenerationNumberByObjectId(). - Use only information from the last trailer dictionary when parsing incremental updates.
- Write correct cross-reference if only the trailer was updated.
Tweak
- Added various checks for a valid key-length in
SecHandler\SecHandlerandSecHandler\AbstractHandlerclass. - Streamlined all setter methods in
Page\Annotationclasses to use the fluent-interface. - Improved documentation of various methods return types.
- Ensured compatibility with PHP 8.6.
- Dropped support for PHP 7.1.
- Optimized plausibility checks for cross-reference stream length (bring back support for some faulty cross-reference streams).
Version 2.53.0.2374
Release date: 2026-09-16
| Filename | Download | Composer
[ ? Use following minimal composer.json file to install a package through Composer. |
Information |
|---|
SetaPDF-Core Component
Bugfix
- Clean up generated tmp files in
SecHandler\PublicKey. - Fixed
TypeErrorinDocument\Action\Action::addNext()which was triggered when called on an action without a "Next"-value. - Fixed setting of value in
TextAnnotation::setStateModel()on annotations with an already defined StateModel. - Fixed "Undefined array key" error in
CrossReferenceTable::getGenerationNumberByObjectId(). - Use only information from the last trailer dictionary when parsing incremental updates.
- Write correct cross-reference if only the trailer was updated.
Tweak
- Added various checks for a valid key-length in
SecHandler\SecHandlerandSecHandler\AbstractHandlerclass. - Streamlined all setter methods in
Page\Annotationclasses to use the fluent-interface. - Improved documentation of various methods return types.
- Ensured compatibility with PHP 8.6.
- Dropped support for PHP 7.1.
- Optimized plausibility checks for cross-reference stream length (bring back support for some faulty cross-reference streams).
Version 2.53.0.2374
Release date: 2026-09-16
| Filename | Download | Composer
[ ? Use following minimal composer.json file to install a package through Composer. |
Information |
|---|
SetaPDF-Signer Component
Feature
- Added
[add|get]ForeignStreamArtifact()and[add|get]ForeignStreamArtifactValidationRelatedInfo()methods toDocumentSecurityStoreclass to allow foreign stream artifacts in both DSS and VRI dictionaries (e.g.PBAD_PolicyArtifactsandPBAD_PolicyArtifactfrom ICP Brazil).
Bugfix
- Fixed handling of
$dateTimeargument inX509\Chain::buildPath()to allow\DateTimeImmutable.
SetaPDF-Core Component
Bugfix
- Clean up generated tmp files in
SecHandler\PublicKey. - Fixed
TypeErrorinDocument\Action\Action::addNext()which was triggered when called on an action without a "Next"-value. - Fixed setting of value in
TextAnnotation::setStateModel()on annotations with an already defined StateModel. - Fixed "Undefined array key" error in
CrossReferenceTable::getGenerationNumberByObjectId(). - Use only information from the last trailer dictionary when parsing incremental updates.
- Write correct cross-reference if only the trailer was updated.
Tweak
- Added various checks for a valid key-length in
SecHandler\SecHandlerandSecHandler\AbstractHandlerclass. - Streamlined all setter methods in
Page\Annotationclasses to use the fluent-interface. - Improved documentation of various methods return types.
- Ensured compatibility with PHP 8.6.
- Dropped support for PHP 7.1.
- Optimized plausibility checks for cross-reference stream length (bring back support for some faulty cross-reference streams).
Version 2.53.0.2374
Release date: 2026-09-16
| Filename | Download | Composer
[ ? Use following minimal composer.json file to install a package through Composer. |
Information |
|---|
SetaPDF-Core Component
Bugfix
- Clean up generated tmp files in
SecHandler\PublicKey. - Fixed
TypeErrorinDocument\Action\Action::addNext()which was triggered when called on an action without a "Next"-value. - Fixed setting of value in
TextAnnotation::setStateModel()on annotations with an already defined StateModel. - Fixed "Undefined array key" error in
CrossReferenceTable::getGenerationNumberByObjectId(). - Use only information from the last trailer dictionary when parsing incremental updates.
- Write correct cross-reference if only the trailer was updated.
Tweak
- Added various checks for a valid key-length in
SecHandler\SecHandlerandSecHandler\AbstractHandlerclass. - Streamlined all setter methods in
Page\Annotationclasses to use the fluent-interface. - Improved documentation of various methods return types.
- Ensured compatibility with PHP 8.6.
- Dropped support for PHP 7.1.
- Optimized plausibility checks for cross-reference stream length (bring back support for some faulty cross-reference streams).
