What is CVE-2026-54078?
CVE-2026-54078 is an XML External Entity (XXE) vulnerability in the veraPDF validation model, affecting versions from 1.25.73 up to 1.30.2 and 1.31.71. The flaw exists in the `getRichTextStringOrSt` function within `DictionaryKeysHelper.java`, potentially allowing attackers to exploit XML parsing. It is recommended to update to a patched version immediately.
Azərbaycanca: CVE-2026-54078, veraPDF doğrulama modelində XML External Entity (XXE) zəifliyidir. 1.25.73-dən 1.30.2-yə və 1.31.71-ə qədər versiyalar təsirlənir, xüsusilə `DictionaryKeysHelper.java` faylındakı `getRichTextStringOrSt` funksiyası vasitəsilə istismar oluna bilər. Təsirlənmiş versiyaları dərhal yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-611
FAQ2
Which versions of veraPDF are affected by CVE-2026-54078?
CVE-2026-54078 affects veraPDF versions from 1.25.73 up to 1.30.2 and version 1.31.71.
Which file and function are associated with the CVE-2026-54078 vulnerability?
The vulnerability lies in the `getRichTextStringOrSt` function within `DictionaryKeysHelper.java`.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.