Impact
The flaw is an XML External Entity (XXE) vulnerability that occurs when veraPDF-validation processes a PDF containing a malicious XFA stream. During PDF/UA‑1 validation, the getdynamicRender() method expands external entities, enabling an attacker to read local files on the host or to force the application to send outbound requests to arbitrary servers. This can result in the disclosure of sensitive data and potential networking exposure. The CVSS score of 8.7 reflects the high impact of this abuse.
Affected Systems
Vendors and products affected are veraPDF by veraPDF – specifically the veraPDF‑validation component. Versions from 1.17.35 up through 1.30.1 and prior to 1.31.71 are vulnerable. All releases older than 1.30.2 and before 1.31.71 should be considered at risk until the fix is applied.
Risk and Exploitability
With an EPSS score of less than 1%, the likelihood of exploitation in the wild is low, but the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation at the time of this analysis. The attack vector is inferred to require that a malicious PDF reach the veraPDF-validation process, which is typically performed in an internal scanning or validation workflow. An attacker could therefore place a crafted PDF in a repository that the validation service scans to gain local file disclosure or to trigger unauthorized outbound network activity. The overall risk is considered moderate due to the specific prerequisite of PDF processing and the limited exploitation probability.
OpenCVE Enrichment
Github GHSA