NONE · 0

CVE-2026-54078

veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity (XXE) vulnerability in validati...

Vulnerability Description

veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity (XXE) vulnerability in validation-model/src/main/java/org/verapdf/gf/model/tools/DictionaryKeysHelper.java in getRichTextStringOrStreamEntryStringRepresentation(), where a crafted PDF containing a malicious rich-text /RC or /RV entry can cause external entity expansion and reflect local file contents into the validation report. This issue is fixed in versions 1.30.2 and 1.31.71.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-54078?

CVE-2026-54078 is a documented vulnerability. veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity (XXE) vulnerability in validati...

How severe is CVE-2026-54078?

CVSS scoring is not yet available for CVE-2026-54078. Check NVD for updates.

Is there a patch for CVE-2026-54078?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.