THREAT OPS › Threat News › [GHSA] GHSA-36mm-w85j-3q2j (high) — veraPDF Validation XXE via XFA
[GHSA] GHSA-36mm-w85j-3q2j (high) — veraPDF Validation XXE via XFA
GHSA-36mm-w85j-3q2j Severity: high CVE: CVE-2026-54079
veraPDF Validation XXE via XFA
## Summary
**Description** An XML External Entity Injection (CWE-611) vulnerability in veraPDF allows a remote attacker to read arbitrary files on the server file system and perform Server-Side Request Forgery by submitting a crafted PDF containing a malicious XFA stream. This affects all current versions
Indicators of compromise
- CVE-2026-54079cve
Original source: https://github.com/advisories/GHSA-36mm-w85j-3q2j