PT-2026-63555 · Dompdf · Dompdf
CVE-2026-59943
·
Published
2026-07-22
·
Updated
2026-07-28
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Dompdf versions 3.x and earlier
Description
An issue exists where a malicious actor providing unrestricted content for rendering can leak filesystem information. By using an
<image> element within a data-URI encoded SVG document, an attacker can attempt to embed local files via the href or xlink:href attributes. The system behaves differently when processing a file that does not exist compared to when accessing a file or directory that actually exists on the filesystem, allowing an attacker to confirm the existence of specific files and directories on the backend.Recommendations
Update to version 3.16.
Exploit
Fix
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dompdf