Moderate severityNVD Advisory· Published Jul 29, 2026· Updated Jul 30, 2026
veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs
CVE-2026-54082
Description
veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity vulnerability in PDFAValidator.validate(...) and GFPDAcroForm.getdynamicRender(), where default DocumentBuilderFactory parsing of rich-text annotation or form-field values and XFA configurations in untrusted PDFs can allow local file disclosure and outbound network requests. This issue is fixed in versions 1.30.2 and 1.31.71.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.verapdf:validation-modelMaven | >= 1.17.35, < 1.30.2 | 1.30.2 |
org.verapdf:validation-modelMaven | >= 1.31.1, < 1.31.71 | 1.31.71 |
org.verapdf:validation-model-jakartaMaven | >= 1.17.35, < 1.30.2 | 1.30.2 |
org.verapdf:validation-model-jakartaMaven | >= 1.31.1, < 1.31.71 | 1.31.71 |
Affected products
1Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-cg9x-g3gm-h5h6ghsaADVISORY
- github.com/veraPDF/veraPDF-validation/commit/94caa46c1a594512247fbd46c808edae39469542ghsax_refsource_MISCWEB
- github.com/veraPDF/veraPDF-validation/commit/cacd9436d0de40b0e58cc7d2dbb06451619e61ecghsax_refsource_MISCWEB
- github.com/veraPDF/veraPDF-validation/pull/730ghsax_refsource_MISCWEB
- github.com/veraPDF/veraPDF-validation/security/advisories/GHSA-cg9x-g3gm-h5h6ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.