{"id":"GHSA-36mm-w85j-3q2j","summary":"veraPDF Validation XXE via XFA","details":"## Summary  \n  \n**Description**\nAn XML External Entity Injection (CWE-611) vulnerability in veraPDF allows a remote attacker to read arbitrary files on the server file system and perform Server-Side Request Forgery by submitting a crafted PDF containing a malicious XFA stream. This affects all current versions of veraPDF-validation.  \n  \n## Details  \nThe vulnerability resides in veraPDF-validation `validation-model/src/main/java/org/verapdf/gf/model/impl/pd/GFPDAcroForm.java` within the `getdynamicRender()` method. This method retrieves the /XFA entry from the PDF's /AcroForm dictionary, decodes the embedded XML stream, and parses it to extract the `\u003cdynamicRender\u003e` element value.  \n  \nThe vulnerability stems from the use of a default-configured `DocumentBuilderFactory` to parse fully attacker-controlled XML:  \n- The factory is created via `DocumentBuilderFactory.newInstance()` with no security features enabled. disallow-doctype-decl, external-general-entities, external-parameter-entities, and FEATURE_SECURE_PROCESSING are all left at their insecure defaults.  \n- The input passed to `builder.parse()` is the decoded /XFA stream taken directly from the untrusted PDF.  \n- The text content of the `\u003cdynamicRender\u003e` node is returned to the validation model. Note that the shipped PDF/UA-1 rule (`dynamicRender != 'required'`) consumes this value but does not echo it into the report output, so reliable exfiltration requires the out-of-band parameter-entity technique described under Impact rather than in-band reflection.  \n  \n## Impact  \n  \nThis impacts all current releases of the veraPDF validation-model module.  \n  \nSuccessful exploitation requires only that the target validate an attacker-supplied PDF against the PDF/UA-1 profile (or via flavour auto-detection on a PDF that declares PDF/UA-1 conformance), since `getdynamicRender()` is invoked by the `dynamicRender != 'required'` rule in the bundled PDF/UA-1 profile. No additional configuration or operator action is required.  \n    \n## Proposed Patch  \n  \nHarden the `DocumentBuilderFactory` in `validation-model/src/main/java/org/verapdf/gf/model/impl/pd/GFPDAcroForm.java` per the OWASP XXE Prevention Cheat Sheet to disallow DOCTYPE outright.","aliases":["CVE-2026-54079"],"modified":"2026-07-29T15:27:32.474584Z","published":"2026-07-29T15:08:17Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-07-29T15:08:17Z","nvd_published_at":null,"cwe_ids":["CWE-611"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/veraPDF/veraPDF-validation/security/advisories/GHSA-36mm-w85j-3q2j"},{"type":"WEB","url":"https://github.com/veraPDF/veraPDF-validation/pull/730"},{"type":"WEB","url":"https://github.com/veraPDF/veraPDF-validation/commit/94caa46c1a594512247fbd46c808edae39469542"},{"type":"WEB","url":"https://github.com/veraPDF/veraPDF-validation/commit/cacd9436d0de40b0e58cc7d2dbb06451619e61ec"},{"type":"PACKAGE","url":"https://github.com/veraPDF/veraPDF-validation"}],"affected":[{"package":{"name":"org.verapdf:validation-model","ecosystem":"Maven","purl":"pkg:maven/org.verapdf/validation-model"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.17.35"},{"fixed":"1.30.2"}]}],"versions":["1.18.1","1.18.2","1.18.7","1.18.8","1.20.1","1.20.2","1.22.1","1.22.2","1.24.1","1.24.2","1.26.1","1.26.2","1.26.5","1.28.1","1.28.2","1.30.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-36mm-w85j-3q2j/GHSA-36mm-w85j-3q2j.json","last_known_affected_version_range":"\u003c= 1.30.1"}},{"package":{"name":"org.verapdf:validation-model","ecosystem":"Maven","purl":"pkg:maven/org.verapdf/validation-model"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.31.1"},{"fixed":"1.31.71"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 1.31.70","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-36mm-w85j-3q2j/GHSA-36mm-w85j-3q2j.json"}},{"package":{"name":"org.verapdf:validation-model-jakarta","ecosystem":"Maven","purl":"pkg:maven/org.verapdf/validation-model-jakarta"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.17.35"},{"fixed":"1.30.2"}]}],"versions":["1.24.1","1.24.2","1.26.1","1.26.2","1.26.5","1.28.1","1.28.2","1.30.1"],"database_specific":{"last_known_affected_version_range":"\u003c= 1.30.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-36mm-w85j-3q2j/GHSA-36mm-w85j-3q2j.json"}},{"package":{"name":"org.verapdf:validation-model-jakarta","ecosystem":"Maven","purl":"pkg:maven/org.verapdf/validation-model-jakarta"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.31.1"},{"fixed":"1.31.71"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-36mm-w85j-3q2j/GHSA-36mm-w85j-3q2j.json","last_known_affected_version_range":"\u003c= 1.31.70"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}