What is CVE-2026-54079?
CVE-2026-54079 is an XML External Entity (XXE) vulnerability in the veraPDF library during PDF validation, specifically in the GFPDACroForm.java component. It affects versions from 1.17.35 up to 1.30.2 and 1.31.71. Users are advised to upgrade to a patched version immediately.
Azərbaycanca: CVE-2026-54079, veraPDF kitabxanasında PDF fayllarının yoxlanılması zamanı XML External Entity (XXE) zəifliyidir. Bu, xüsusilə GFPDACroForm.java faylında mövcuddur və 1.17.35-dən 1.30.2-ə qədər, həmçinin 1.31.71 versiyalarına təsir edir. İstifadəçilərə dərhal yeni versiyaya yüksəlmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-611
FAQ2
Which veraPDF versions are affected by CVE-2026-54079?
This vulnerability affects veraPDF versions from 1.17.35 up to 1.30.2, as well as version 1.31.71.
In which veraPDF component does CVE-2026-54079 exist?
CVE-2026-54079 is an XML External Entity (XXE) vulnerability that exists in the GFPDACroForm.java component of the veraPDF library.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.