Security fixes are made on the latest main branch and the newest published release.
Please do not open a public issue or pull request with vulnerability details. Use GitHub's private vulnerability reporting form.
Include a short description, affected version or commit, impact, and reproduction steps or a minimal proof of concept. Do not include private documents, personal information, access tokens, or signing keys.
Reports are reviewed by the maintainers. Please allow reasonable time for verification and a fix before public disclosure.
For non-security bugs, use the public bug report form.
ClearPDF processes selected documents locally and does not provide a document-upload service. The FOSS build can make requests for the optional Office engine download and when converting a web address you enter to PDF. See PRIVACY.md for details.