THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-cg9x-g3gm-h5h6 (medium) — veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs

[GHSA] GHSA-cg9x-g3gm-h5h6 (medium) — veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs

medgithub_advisoriesPublished 2026-07-29

GHSA-cg9x-g3gm-h5h6 Severity: medium CVE: CVE-2026-54082

veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs

### Summary

veraPDF-validation has an XML External Entity (XXE) vulnerability in two PDF parsing paths (validate and `GFPDAcroForm.getdynamicRender()`). A malicious/crafted PDF supplied to a veraPDF consumer can lead to the expansion of

Indicators of compromise

Original source: https://github.com/advisories/GHSA-cg9x-g3gm-h5h6