HIGH: org.verapdf:validation-model — veraPDF Validation XXE via Rich Text
Summary Description An XML External Entity Injection (CWE-611) vulnerability in veraPDF allows a remote attacker to read arbitrary files on the server file system and perform Server-Side Request Forgery by submitting a crafted PDF containing a malicious…
Source org.verapdf:validation-modelPublished 6d ago · Jul 29, 2026Posted on Threads

What we hold
- Package
- org.verapdf:validation-model
- Ecosystem
- maven
- Severity
- HIGH
- ID
- CVE-2026-54078
Summary Description An XML External Entity Injection (CWE-611) vulnerability in veraPDF allows a remote attacker to read arbitrary files on the server file system and perform Server-Side Request Forgery by submitting a crafted PDF containing a malicious…