Bounded PDF Parser Budgets
Document-scoped parser budgets stop hostile or damaged input before token construction, aggregate token work, array or dictionary growth, or repeated malformed tokens consume excessive resources
Compatibility defaults
ParserMaxTokenBytesdefaults to 67,108,864 bytesParserMaxTotalTokensdefaults to 10,000,000 tokens per loadParserMaxContainerItemsdefaults to 1,000,000 entries per array or dictionaryParserMaxBadTokensdefaults to 64 malformed tokens per load
Set any limit to zero to disable that individual limit
Negative values raise ERangeError
Strict policy
ApplyStrictParserBudgetPolicy selects a 1 MiB token limit, 100,000 total tokens, 10,000 container entries, and 8 malformed tokens
PDF.ApplyStrictParserBudgetPolicy;
try
PDF.LoadFromFile(UntrustedFileName);
except
on E: EHPDFParserBudgetExceeded do
LogParserRejection(E.Limit, E.Observed, E.Maximum);
end;
ResetParserBudgetPolicy restores the compatibility defaults
Failure and telemetry
A breached limit raises EHPDFParserBudgetExceeded with Limit, Observed, and Maximum values
THPDFParserBudgetLimit identifies pblTokenBytes, pblTotalTokens, pblContainerItems, or pblBadTokens
GetLastParserBudgetStatistics returns a THPDFParserBudgetStatistics snapshot with configured limits, token and malformed-token counts, peak token and container sizes, breach information, and session validity
Budget exceptions remain terminal across modern parsing, traditional parsing, cross-reference recovery, and per-object failure isolation
Performance gate
The Win32 regression gate rejects a 2 MiB token in 215 ms at a 34,476,032-byte process peak and rejects a one-million-token container in 199 ms at a 36,839,424-byte process peak
See also: ApplyStrictParserBudgetPolicy, ResetParserBudgetPolicy, GetLastParserBudgetStatistics, Scalable Loading