CVE-2026-54079
veraPDF · veraPDF-validation
The veraPDF validation model is susceptible to an XML External Entity (XXE) attack, which may allow unauthenticated remote attackers to read sensitive files from the underlying system.
Executive summary
A critical XML External Entity (XXE) vulnerability in the veraPDF validation model allows unauthenticated remote attackers to compromise system file confidentiality.
Vulnerability
This is an Improper Restriction of XML External Entity Reference (CWE-611). The vulnerability allows an unauthenticated attacker to manipulate XML processing to gain unauthorized read access to files on the host server.
Business impact
This vulnerability allows for the potential exposure of sensitive information, which could lead to further system compromise or data breaches. With a CVSS score of 8.7, the risk of unauthorized data access is high, necessitating immediate intervention to prevent potential exploitation.
Remediation
Immediate Action: Update the affected veraPDF validation-model and validation-model-jakarta components to version 1.30.2 or 1.31.71.
Proactive Monitoring: Review system and application logs for anomalous XML processing patterns or attempts to access restricted file paths.
Compensating Controls: Use a Web Application Firewall (WAF) to block requests containing XML external entity definitions.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Due to the severity of this vulnerability, immediate patching is required. Organizations should update to the provided fixed versions to remove the risk of file disclosure. Ensure that all downstream dependencies using the veraPDF validation model are also updated.