CVE-2026-54079
Received Received - Intake

XML External Entity Injection in veraPDF Validation

Vulnerability report for CVE-2026-54079, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-29

Last updated on: 2026-07-29

Assigner: GitHub, Inc.

Description

veraPDF validation provides PDF/A and PDF/UA validation, feature reporting, and metadata repair. From 1.17.35 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity (XXE) vulnerability in validation-model/src/main/java/org/verapdf/gf/model/impl/pd/GFPDAcroForm.java in the getdynamicRender() method, where a crafted PDF containing a malicious XFA stream can cause external entity expansion during PDF/UA-1 validation and allow local file disclosure or outbound server-side requests. This issue is fixed in versions 1.30.2 and 1.31.71.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-29
Last Modified
2026-07-29
Generated
2026-07-30
AI Q&A
2026-07-30
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
verapdf verapdf_validation From 1.17.35 (inc) to 1.30.2 (exc)
verapdf verapdf_validation 1.30.2
verapdf verapdf_validation 1.31.71

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-611 The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an XML External Entity (XXE) vulnerability in veraPDF validation software. It affects versions between 1.17.35 and 1.30.2, and 1.31.71. A crafted PDF with a malicious XFA stream can trigger external entity expansion during PDF/UA-1 validation, potentially leading to local file disclosure or outbound server-side requests.

Detection Guidance

Detecting this XXE vulnerability requires checking for affected veraPDF validation versions (1.17.35 to 1.30.2 and 1.31.71) and analyzing PDF files for malicious XFA streams during PDF/UA-1 validation. No specific commands are provided in the context.

Impact Analysis

An attacker could exploit this to read sensitive files on your system or make unauthorized network requests from your server. This could lead to data breaches, information leakage, or further compromise of your infrastructure.

Compliance Impact

This vulnerability could violate compliance requirements by enabling unauthorized data access or disclosure. GDPR and HIPAA both mandate protection of personal and health data, respectively. Exploitation could lead to regulatory penalties, fines, or legal consequences due to compromised data integrity and confidentiality.

Mitigation Strategies

Upgrade veraPDF validation to versions 1.30.2 or 1.31.71 or later to address the XXE vulnerability. Disable PDF/UA-1 validation for untrusted PDFs if immediate upgrade is not possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54079. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart