CVE-2026-54082
Received Received - Intake

XML External Entity in veraPDF Validation Model

Vulnerability report for CVE-2026-54082, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-29

Last updated on: 2026-07-29

Assigner: GitHub, Inc.

Description

veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity vulnerability in PDFAValidator.validate(...) and GFPDAcroForm.getdynamicRender(), where default DocumentBuilderFactory parsing of rich-text annotation or form-field values and XFA configurations in untrusted PDFs can allow local file disclosure and outbound network requests. This issue is fixed in versions 1.30.2 and 1.31.71.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-29
Last Modified
2026-07-29
Generated
2026-07-30
AI Q&A
2026-07-30
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
verapdf verapdf_validation From 1.25.73 (inc) to 1.30.2 (inc)
verapdf verapdf_validation 1.31.71

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-611 The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an XML External Entity (XXE) flaw in the veraPDF validation model. It exists in versions 1.25.73 through 1.30.2 and 1.31.71. The issue allows parsing of untrusted PDF content like rich-text annotations or form-field values, which can lead to local file disclosure or outbound network requests.

Detection Guidance

Detecting this vulnerability requires checking the version of veraPDF-validation installed on your system. If you are using a version between 1.25.73 and 1.30.2 or 1.31.71, your system is vulnerable. Run the command 'verapdf --version' to check the installed version.

Impact Analysis

An attacker could exploit this to read sensitive files on your system or make unauthorized network requests. This could expose confidential data or allow further attacks if combined with other vulnerabilities.

Compliance Impact

This vulnerability could lead to unauthorized data exposure, violating GDPR's data protection principles or HIPAA's security requirements for protected health information. Organizations using affected versions may face compliance risks.

Mitigation Strategies

Immediately upgrade veraPDF-validation to version 1.30.2 or 1.31.71 or later. Avoid processing untrusted PDFs until the update is applied. Monitor network traffic for unusual outbound requests or local file access patterns.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54082. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart