Vendor
high
advisory
veraPDF Validation XXE via Rich Text
3 TTPsAn XML External Entity (XXE) injection vulnerability (CVE-2026-54078, CWE-611) in the veraPDF-validation library's `validation-model` module allows a remote attacker to read arbitrary files from the server's file system and perform Server-Side Request Forgery by submitting a crafted PDF containing a malicious rich-text entry, which is then parsed by an insecure `DocumentBuilderFactory`.
validation-model +3
xml-external-entity-injection
xxe
server-side-request-forgery
ssrf
pdf
java
3t
high
advisory
veraPDF Validation Module XML External Entity Injection Vulnerability (CVE-2026-54079)
4 TTPsA critical XML External Entity Injection (XXE) vulnerability, CVE-2026-54079, in veraPDF's validation-model module allows a remote attacker to read arbitrary files on the server file system or perform Server-Side Request Forgery (SSRF) by submitting a crafted PDF containing a malicious XFA stream, due to insecure XML parsing defaults.
veraPDF validation-model +3
xxe
xml-external-entity
pdf
server-side-request-forgery
vulnerability
4t