PT-2026-63555 · Dompdf · Dompdf

CVE-2026-59943

·

Published

2026-07-22

·

Updated

2026-07-28

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Dompdf versions 3.x and earlier
Description An issue exists where a malicious actor providing unrestricted content for rendering can leak filesystem information. By using an <image> element within a data-URI encoded SVG document, an attacker can attempt to embed local files via the href or xlink:href attributes. The system behaves differently when processing a file that does not exist compared to when accessing a file or directory that actually exists on the filesystem, allowing an attacker to confirm the existence of specific files and directories on the backend.
Recommendations Update to version 3.16.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59943
GHSA-J8QW-6JW8-R297

Affected Products

Dompdf