CVE-2024-52800

low
Published 2024-12-02 · Modified 2026-05-14
CVSS v3
CVSS v2
VIR risk
2.5

Description

veraPDF CLI has potential XXE (XML External Entity Injection) vulnerability

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.verapdf:core<1.26.21.26.2
java Mavenorg.verapdf:core-jakarta<1.26.21.26.2
java Mavenorg.verapdf:core-arlington<1.26.21.26.2
java Mavenorg.verapdf:verapdf-library<1.26.21.26.2
java Mavenorg.verapdf:verapdf-library-jakarta<1.26.21.26.2
java Mavenorg.verapdf:verapdf-library-arlington<1.26.21.26.2
java Mavenorg.verapdf:library<1.26.21.26.2
java Mavenorg.verapdf:library-jakarta<1.26.21.26.2
java Mavenorg.verapdf:library-arlington<1.26.21.26.2
java MAVENorg.verapdf:library-arlington<= 1.26.11.26.2
java MAVENorg.verapdf:library-jakarta<= 1.26.11.26.2
java MAVENorg.verapdf:library<= 1.26.11.26.2
java MAVENorg.verapdf:verapdf-library<= 1.26.11.26.2
java MAVENorg.verapdf:verapdf-library-arlington<= 1.26.11.26.2
java MAVENorg.verapdf:verapdf-library-jakarta<= 1.26.11.26.2
java MAVENorg.verapdf:core-arlington<= 1.26.11.26.2
java MAVENorg.verapdf:core-jakarta<= 1.26.11.26.2
java MAVENorg.verapdf:core<= 1.26.11.26.2

References

Verify integrity in audit chain (admin only). AS-IS.