Back to CVE List

CVE-2026-54078

HIGH SEVERITY

Vulnerability Description

veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity (XXE) vulnerability in validation-model/src/main/java/org/verapdf/gf/model/tools/DictionaryKeysHelper.java in getRichTextStringOrStreamEntryStringRepresentation(), where a crafted PDF containing a malicious rich-text /RC or /RV entry can cause external entity expansion and reflect local file contents into the validation report. This issue is fixed in versions 1.30.2 and 1.31.71.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-611
Source
NVD
Vendor
veraPDF
Product
veraPDF-validation

External References

Discussion (0)

Add Comment

No comments yet. Be the first!