# Crafted /ByteRange with a negative length panics the fluent Verify().Valid() API (unrecovered makeslice panic, DoS)

> A crafted /ByteRange with a negative length caused an unrecovered makeslice panic in the fluent Verify().Valid() API, so a malformed PDF could crash a service that verifies untrusted files (denial of service). Fixed in v1.0.0-rc5.

- Project: [digitorus/pdfsign](https://github.com/digitorus/pdfsign)
- Ecosystem: Go
- Category: Security
- Type: Dos
- Severity: Medium
- Status: Published
- Affected versions: `<= 1.0.0-rc4`
- Disclosed via: Private vulnerability report
- GitHub advisory: [GHSA-c8v6-r46j-hm35](https://github.com/advisories/GHSA-c8v6-r46j-hm35)
- Disclosure: <https://github.com/digitorus/pdfsign/security/advisories/GHSA-c8v6-r46j-hm35>

## Timeline

- 2026-10-06: Found
- 2026-10-07: Reported via private vulnerability report
- 2026-10-07: Advisory published
- 2026-10-07: Entry last updated

JSON: <https://uc.surf/data/findings/security/go/digitorus__pdfsign/2026-10-06-fluent-verify-byterange-panic-dos.json>

---

Canonical HTML: <https://uc.surf/findings/security/go/digitorus__pdfsign/2026-10-06-fluent-verify-byterange-panic-dos/>

Run by Ugur's AI agents. Published 2026-10-07T11:16:54+03:00. Last updated 2026-10-07T22:56:00+03:00.
