PULSE
EN VIVO14señales / 24h
FEED
ransomthegentlemen reclama a Promatrix · US · Technologyransomthegentlemen reclama a Malaysian Nuclear Agency · MY · Government & Defenseransomthegentlemen reclama a Delkart Industries Pvt · IN · Manufacturingransomthegentlemen reclama a ETA Technology Pvt · IN · Technologyransomthegentlemen reclama a Kontact Consortium India Pvt · IN · Otherransomthegentlemen reclama a Upanal CNC Solutions · PE · Manufacturingransomthegentlemen reclama a Indus Protech Solutions · IN · Technologyransomthegentlemen reclama a Angel Hotel · GB · Hospitalityransomthegentlemen reclama a The Garfield County Sheriff Office · US · Government & Defenseransommorpheus reclama a Yue Ki Industrial · TW · Manufacturingransomincransom reclama a harwal.net · AE · Not Foundransomakira reclama a Northwood Country Club · Hospitalityransomsection9 reclama a ****.com.pa · PA · Not Foundransomspacebears reclama a StellarRAD Systems · US · Technologyransomthegentlemen reclama a Promatrix · US · Technologyransomthegentlemen reclama a Malaysian Nuclear Agency · MY · Government & Defenseransomthegentlemen reclama a Delkart Industries Pvt · IN · Manufacturingransomthegentlemen reclama a ETA Technology Pvt · IN · Technologyransomthegentlemen reclama a Kontact Consortium India Pvt · IN · Otherransomthegentlemen reclama a Upanal CNC Solutions · PE · Manufacturingransomthegentlemen reclama a Indus Protech Solutions · IN · Technologyransomthegentlemen reclama a Angel Hotel · GB · Hospitalityransomthegentlemen reclama a The Garfield County Sheriff Office · US · Government & Defenseransommorpheus reclama a Yue Ki Industrial · TW · Manufacturingransomincransom reclama a harwal.net · AE · Not Foundransomakira reclama a Northwood Country Club · Hospitalityransomsection9 reclama a ****.com.pa · PA · Not Foundransomspacebears reclama a StellarRAD Systems · US · Technology
← Todos los CVEs
CVE Watch29 jul 2026

CVE-2026-54078

veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation con

CVSS

Sin CVSS

EPSS

KEV

Exploit Today

0-100

Publicado: 29 jul 2026 · Última mod.: 29 jul 2026 · CWE-611

EPSS · 30d

Sin historial EPSS suficiente todavía.

Descripción técnica

veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity (XXE) vulnerability in validation-model/src/main/java/org/verapdf/gf/model/tools/DictionaryKeysHelper.java in getRichTextStringOrStreamEntryStringRepresentation(), where a crafted PDF containing a malicious rich-text /RC or /RV entry can cause external entity expansion and reflect local file contents into the validation report. This issue is fixed in versions 1.30.2 and 1.31.71.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-540826.5 MED
veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity vulnerability in PDFAValidator.validate(...) and GFPDAcroForm.getdynamicRender(), where default DocumentBuilderFactory parsing of rich-text annotation or form-field values and XFA configurations in untrusted PDFs can allow local file disclosure and outbound network requests. This issue is fixed in versions 1.30.2 and 1.31.71.15h
CVE-2026-54079
veraPDF validation provides PDF/A and PDF/UA validation, feature reporting, and metadata repair. From 1.17.35 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity (XXE) vulnerability in validation-model/src/main/java/org/verapdf/gf/model/impl/pd/GFPDAcroForm.java in the getdynamicRender() method, where a crafted PDF containing a malicious XFA stream can cause external entity expansion during PDF/UA-1 validation and allow local file disclosure or outbound server-side requests. This issue is fixed in versions 1.30.2 and 1.31.71.15h
CVE-2026-57917
3.3%
1proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling SSRF and potentially allowing the reading of local files, depending on the parser's configuration. The XML External Entity (XXE) vulnerability is triggered simply by previewing a file in the file selection window, before the victim clicks “Open”. This issue was fixed in version 9.4.3.90.3d
CVE-2026-56817
24.4%
7Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that can deliver bytes to a Netty channel pipeline containing `XmlDecoder` can send XML with a `DOCTYPE` declaration to an `AsyncXMLInputFactory` instantiated with no security configuration, leaving DTD and entity handling active depending on Aalto XML async parser behavior and creating conditional XML external entity risk. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.7d
CVE-2026-510809.8 CRÍ
22.3%
7libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability.13d
CVE-2026-83967.5 ALT
17.6%
5Improper restriction of XML external entity reference vulnerability in Netcad Software Inc. NetGIS allows Serialized Data External Linking. This issue affects NetGIS: from 5.0.66 before 7.2.2.13d