CVE-2026-54082: veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs
veraPDF-validation has an XML External Entity (XXE) vulnerability in two PDF parsing paths (validate and GFPDAcroForm.getdynamicRender()). A malicious/crafted PDF supplied to a veraPDF consumer can lead to the expansion of external entities while parsing rich-text annotation/form-field values or XFA configurations, allowing local file disclosure and potentially outbound network requests depending on the runtime (host) environment.
References
- github.com/advisories/GHSA-cg9x-g3gm-h5h6
- github.com/veraPDF/veraPDF-validation/commit/94caa46c1a594512247fbd46c808edae39469542
- github.com/veraPDF/veraPDF-validation/commit/cacd9436d0de40b0e58cc7d2dbb06451619e61ec
- github.com/veraPDF/veraPDF-validation/pull/730
- github.com/veraPDF/veraPDF-validation/security/advisories/GHSA-cg9x-g3gm-h5h6
- nvd.nist.gov/vuln/detail/CVE-2026-54082
Code Behaviors & Features
Detect and mitigate CVE-2026-54082 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →