Junglewise Threat Intelligence

CVE-2026-54078: veraPDF XXE vulnerability in rich-text validation

CVE-2026-54078 · Severity: high · CVSS 4 · Published 2026-07-29

Technologies: veraPDF Validation-Model-Jakarta, veraPDF-validation, veraPDF Validation-Model. Vendors: veraPDF.

Executive brief

veraPDF is an open-source software library used to validate PDF files against industry standards. A security flaw allows an attacker to provide a specially crafted PDF file that, when processed by the software, can trick the system into revealing sensitive local files or performing unauthorized internal network requests. This could lead to the exposure of confidential data or provide a foothold for further attacks on the organization's infrastructure.

Technical details

An XML External Entity (XXE) vulnerability exists in the veraPDF-validation library, specifically within the DictionaryKeysHelper.java component's getRichTextStringOrStreamEntryStringRepresentation() method. The root cause is an insecurely configured DocumentBuilderFactory that fails to disable DTDs or external entity resolution when parsing XHTML rich-text (/RC or /RV) entries from PDF dictionaries. An attacker can exploit this by submitting a crafted PDF containing malicious XML entities; the parser will resolve these entities and reflect the contents of local files or internal network resources directly into the resulting validation report. The issue has been addressed in versions 1.30.2 and 1.31.71 by implementing secure XML parsing defaults.

Affected products

  • veraPDF veraPDF-validation >= 1.25.73, < 1.30.2; >= 1.31.1, < 1.31.71
  • veraPDF validation-model-jakarta >= 1.25.73, < 1.30.2; >= 1.31.1, < 1.31.71

Timeline

  • 2026-05-28: patched: Fix merged into integration branch
  • 2026-06-08: advisory: GitHub Security Advisory published
  • 2026-07-29: disclosed: CVE published to NVD

References

Related threats