CVE-2026-54079: veraPDF Validation XXE via XFA
Description An XML External Entity Injection (CWE-611) vulnerability in veraPDF allows a remote attacker to read arbitrary files on the server file system and perform Server-Side Request Forgery by submitting a crafted PDF containing a malicious XFA stream. This affects all current versions of veraPDF-validation.
References
- github.com/advisories/GHSA-36mm-w85j-3q2j
- github.com/veraPDF/veraPDF-validation/commit/94caa46c1a594512247fbd46c808edae39469542
- github.com/veraPDF/veraPDF-validation/commit/cacd9436d0de40b0e58cc7d2dbb06451619e61ec
- github.com/veraPDF/veraPDF-validation/pull/730
- github.com/veraPDF/veraPDF-validation/security/advisories/GHSA-36mm-w85j-3q2j
- nvd.nist.gov/vuln/detail/CVE-2026-54079
Code Behaviors & Features
Detect and mitigate CVE-2026-54079 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →