{"id":"CVE-2026-54079","description":"veraPDF validation provides PDF/A and PDF/UA validation, feature reporting, and metadata repair. From 1.17.35 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity (XXE) vulnerability in validation-model/src/main/java/org/verapdf/gf/model/impl/pd/GFPDAcroForm.java in the getdynamicRender() method, where a crafted PDF containing a malicious XFA stream can cause external entity expansion during PDF/UA-1 validation and allow local file disclosure or outbound server-side requests. This issue is fixed in versions 1.30.2 and 1.31.71.","cvssScore":8.7,"cvssVersion":"4.0","cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","cvssMetrics":[{"version":"4.0","score":8.7,"severity":"HIGH","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","source":"security-advisories@github.com","type":"Secondary"}],"cwes":["CWE-611"],"resolved":"MITIGATED-BY-RASP","published":"2026-07-29","lastModified":"2026-07-30","references":[{"url":"https://github.com/veraPDF/veraPDF-validation/commit/94caa46c1a594512247fbd46c808edae39469542","source":"patch-hint","tags":["commit"]},{"url":"https://github.com/veraPDF/veraPDF-validation/security/advisories/GHSA-36mm-w85j-3q2j","source":"osv","tags":["WEB"]},{"url":"https://github.com/veraPDF/veraPDF-validation/pull/730","source":"osv","tags":["WEB"]},{"url":"https://github.com/veraPDF/veraPDF-validation/commit/cacd9436d0de40b0e58cc7d2dbb06451619e61ec","source":"osv","tags":["WEB"]},{"url":"https://github.com/veraPDF/veraPDF-validation","source":"osv","tags":["PACKAGE"]}],"reasoning":{"decidingSource":"secure-rule-match","decidingReason":"Promoted to MITIGATED-BY-RASP (security rule): this CVE's weakness (CWE-611: XML External Entity Reference) can be mitigated by an ARMR xxe security rule that blocks this class of attack at the JVM level, without requiring a CVE-specific patch.","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"no-match"},{"rule":"non-java-upstream","stage":"scope","outcome":"no-match"},{"rule":"oracle-component","stage":"scope","outcome":"no-match"},{"rule":"osv-maven","stage":"scope","outcome":"matched","status":"QUEUED-FOR-REVIEW","detail":"Maven packages: org.verapdf:validation-model, org.verapdf:validation-model-jakarta"},{"rule":"patch-hint","stage":"disposition","outcome":"matched","status":"MITIGATION-CANDIDATE","detail":"References include candidate fix URL (commit tier): https://github.com/veraPDF/veraPDF-validation/commit/94caa46c1a594512247fbd46c808edae39469542"},{"rule":"open-source-maven","stage":"disposition","outcome":"skipped"},{"rule":"poc-derivable","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit","stage":"disposition","outcome":"skipped"},{"rule":"secure-rule-match","stage":"disposition","outcome":"matched","status":"MITIGATED-BY-RASP","detail":"CWE-611 (XML External Entity Reference) is mitigable by an ARMR xxe security rule.","decisive":true},{"rule":"below-action-threshold","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit-published","stage":"disposition","outcome":"skipped"}],"patchHintUrl":"https://github.com/veraPDF/veraPDF-validation/commit/94caa46c1a594512247fbd46c808edae39469542","patchHintTier":"commit","affectedPackages":[{"name":"org.verapdf:validation-model","introduced":"1.17.35","fixed":"1.30.2"},{"name":"org.verapdf:validation-model","introduced":"1.31.1","fixed":"1.31.71"},{"name":"org.verapdf:validation-model-jakarta","introduced":"1.17.35","fixed":"1.30.2"},{"name":"org.verapdf:validation-model-jakarta","introduced":"1.31.1","fixed":"1.31.71"}]},"assessment":{"record":{"state":"active"},"protection":{"level":"full","mechanisms":["security-rule"]},"action":{"state":"available","type":"security-rule"},"review":{"state":"automated","basis":"inferred"}},"signals":{"hasPOC":false,"pocCount":0},"kev":{"inKEV":false},"epss":{"available":true,"score":0.0032,"percentile":0.24765},"ssvc":{"available":true,"exploitation":"none","automatable":"yes","technicalImpact":"partial"},"patchHintUrl":"https://github.com/veraPDF/veraPDF-validation/commit/94caa46c1a594512247fbd46c808edae39469542","patchHintTier":"commit"}