Threat Advisory

VeraPDF Parser Vulnerability Enables Denial Service

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in veraPDF, specifically in the parser and validation model, affecting versions 1.30.1 and below, as well as versions 1.31.1 through 1.31.22 and 1.31.70, with vulnerability types including Denial of Service (DoS) and XML External Entity (XXE) injection, posing a significant business risk and impact due to potential exploitation by remote attackers.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in veraPDF, specifically in the parser and validation model, affecting versions 1.30.1 and below, as well as versions 1.31.1 through 1.31.22 and 1.31.70, with vulnerability types including Denial of Service (DoS) and XML External Entity (XXE) injection, posing a significant business risk and impact due to potential exploitation by remote attackers.[emaillocker id="1283"]

  • CVE-2026-54081 with a CVSS score of 5.5 – This vulnerability is a Denial of Service (DoS) issue in veraPDF-parser, where a crafted Type 1 font /FontDescriptor /FontFile program can execute unbounded PostScript array allocation or a zero-increment for loop, exhausting validator memory or CPU.
    • CVE-2026-54080 with a CVSS score of 5.5 – This is another DoS vulnerability in veraPDF-parser, where a crafted Type 0 font /Encoding or /ToUnicode CMap stream can execute unbounded PostScript array allocation or a zero-increment for loop, also exhausting validator memory or CPU.
    • CVE-2026-54082 with a CVSS score of 6.5 – This vulnerability is an XXE injection issue in veraPDF-validation, where a malicious PDF containing a crafted XML external entity can lead to local file disclosure and potentially outbound network requests.
    • CVE-2026-54079 with a CVSS score of 7.5 – This is an XXE injection vulnerability in veraPDF-validation, where a crafted PDF containing a malicious XFA stream can cause external entity expansion during PDF/UA-1 validation, allowing local file disclosure or outbound server-side requests.

The identified vulnerabilities pose a significant risk to businesses, as successful exploitation can lead to denial-of-service conditions, local file disclosure, or server-side request forgery, ultimately resulting in disruption of services, data breaches, or unauthorized access to sensitive information, emphasizing the need for immediate attention and action to mitigate these risks.

RECOMMENDATION:

  • We recommend you to update veraPDF-parser to version 1.31.23.
  • We recommend you to update veraPDF-validation to version 1.31.71.
  • We recommend you to update veraPDF-validation-jakarta to version 1.31.71.

REFERENCES:

The following reports contain further technical details:
https://github.com/advisories/GHSA-7c26-995w-6f47
https://github.com/advisories/GHSA-jrmc-qg6p-94fp
https://github.com/advisories/GHSA-cg9x-g3gm-h5h6
https://github.com/advisories/GHSA-3jh7-wm29-q568
https://github.com/advisories/GHSA-36mm-w85j-3q2j

[/emaillocker]
crossmenu