PT-2026-65825 · Unknown · Verapdf-Validation
CVE-2026-54082
·
Published
2026-07-29
·
Updated
2026-07-29
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
veraPDF-validation versions 1.25.73 through 1.30.1
veraPDF-validation versions 1.31.0 through 1.31.70
Description
An XML External Entity (XXE) issue exists in the parsing of rich-text annotation, form-field values, and XFA configurations in untrusted PDFs. This occurs because the
DocumentBuilderFactory does not disable the parsing of DTDs, external entities, XInclude, or external resource access directives. An attacker can exploit this by providing a crafted PDF to the PDFAValidator.validate(...) or GFPDAcroForm.getdynamicRender() functions, potentially leading to local file disclosure and outbound network requests to attacker-controlled endpoints.Recommendations
Update veraPDF-validation to version 1.30.2.
Update veraPDF-validation to version 1.31.71.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Verapdf-Validation