ADVISORY

HIGH: org.verapdf:validation-model — veraPDF Validation XXE via Rich Text

Summary Description An XML External Entity Injection (CWE-611) vulnerability in veraPDF allows a remote attacker to read arbitrary files on the server file system and perform Server-Side Request Forgery by submitting a crafted PDF containing a malicious…

Source org.verapdf:validation-modelPublished 6d ago · Jul 29, 2026Posted on Threads

What we hold

Package
org.verapdf:validation-model
Ecosystem
maven
Severity
HIGH
ID
CVE-2026-54078

Summary Description An XML External Entity Injection (CWE-611) vulnerability in veraPDF allows a remote attacker to read arbitrary files on the server file system and perform Server-Side Request Forgery by submitting a crafted PDF containing a malicious…