High severityNVD Advisory· Published Jul 29, 2026· Updated Jul 29, 2026
veraPDF Validation XXE via Rich Text
CVE-2026-54078
Description
veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity (XXE) vulnerability in validation-model/src/main/java/org/verapdf/gf/model/tools/DictionaryKeysHelper.java in getRichTextStringOrStreamEntryStringRepresentation(), where a crafted PDF containing a malicious rich-text /RC or /RV entry can cause external entity expansion and reflect local file contents into the validation report. This issue is fixed in versions 1.30.2 and 1.31.71.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.verapdf:validation-modelMaven | >= 1.25.73, < 1.30.2 | 1.30.2 |
org.verapdf:validation-modelMaven | >= 1.31.1, < 1.31.71 | 1.31.71 |
org.verapdf:validation-model-jakartaMaven | >= 1.25.73, < 1.30.2 | 1.30.2 |
org.verapdf:validation-model-jakartaMaven | >= 1.31.1, < 1.31.71 | 1.31.71 |
Affected products
1Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-3jh7-wm29-q568ghsaADVISORY
- github.com/veraPDF/veraPDF-validation/commit/94caa46c1a594512247fbd46c808edae39469542mitrex_refsource_MISC
- github.com/veraPDF/veraPDF-validation/commit/cacd9436d0de40b0e58cc7d2dbb06451619e61ecmitrex_refsource_MISC
- github.com/veraPDF/veraPDF-validation/pull/730mitrex_refsource_MISC
- github.com/veraPDF/veraPDF-validation/security/advisories/GHSA-3jh7-wm29-q568ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.