PT-2026-65825 · Unknown · Verapdf-Validation

CVE-2026-54082

·

Published

2026-07-29

·

Updated

2026-07-29

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions veraPDF-validation versions 1.25.73 through 1.30.1 veraPDF-validation versions 1.31.0 through 1.31.70
Description An XML External Entity (XXE) issue exists in the parsing of rich-text annotation, form-field values, and XFA configurations in untrusted PDFs. This occurs because the DocumentBuilderFactory does not disable the parsing of DTDs, external entities, XInclude, or external resource access directives. An attacker can exploit this by providing a crafted PDF to the PDFAValidator.validate(...) or GFPDAcroForm.getdynamicRender() functions, potentially leading to local file disclosure and outbound network requests to attacker-controlled endpoints.
Recommendations Update veraPDF-validation to version 1.30.2. Update veraPDF-validation to version 1.31.71.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54082
GHSA-CG9X-G3GM-H5H6

Affected Products

Verapdf-Validation