XML External Entity Vulnerability in veraPDF Validation Model by veraPDF
CVE-2026-54082

6.5MEDIUM

Key Information:

Vendor

VeraPDF

Vendor
CVE Published:
29 July 2026

What is CVE-2026-54082?

The veraPDF validation model is affected by an XML External Entity vulnerability that arises during the parsing of rich-text annotations and form-field values from untrusted PDFs. Specifically, this vulnerability exists in the methods PDFAValidator.validate(...) and GFPDAcroForm.getDynamicRender(). Exploiting this flaw can lead to unauthorized local file disclosure and allow untrusted outbound network requests when processing PDF files. The vulnerability has been addressed and is resolved in versions 1.30.2 and 1.31.71.

Affected Version(s)

veraPDF-validation >= 1.17.35, < 1.30.2 < 1.17.35, 1.30.2

veraPDF-validation >= 1.31.1, < 1.31.71 < 1.31.1, 1.31.71

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.