A vulnerability categorized as critical has been discovered in veraPDF validation up to 1.30.1/1.31.70. Affected is the function
getRichTextStringOrStreamEntryStringRepresentation of the file validation-model/src/main/java/org/verapdf/gf/model/tools/DictionaryKeysHelper.java of the component DictionaryKeysHelper. Executing a manipulation can lead to xml external entity reference.
This vulnerability is handled as CVE-2026-54078. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.