dompdf/dompdf Security Advisories for v3.1.4 (6)
-
[MEDIUM] Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem
PKSA-cv56-2228-pzr6 CVE-2026-59943 GHSA-j8qw-6jw8-r297
Affected version: <3.1.6
Reported by:
GitHub -
[MEDIUM] Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
PKSA-6r8f-nxsb-67bq CVE-2026-59942 GHSA-f5gf-2cj8-52g2
Affected version: <3.1.6
Reported by:
GitHub -
[MEDIUM] Dompdf: Uncontrolled resource consumption based on declared BMP dimensions
PKSA-gh7h-hhy4-byg7 CVE-2026-59941 GHSA-8hg6-c449-896m
Affected version: <3.1.6
Reported by:
GitHub -
[MEDIUM] Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI
PKSA-mwt3-h9tv-kx78 CVE-2026-56722 GHSA-cx96-42px-69fm
Affected version: <3.1.6
Reported by:
GitHub -
[LOW] Dompdf: File existence oracle via font-face stylesheet declaration
PKSA-hp6n-n4kz-21wk CVE-2026-55555 GHSA-7x2p-4jvh-6384
Affected version: <3.1.6
Reported by:
GitHub -
[LOW] Dompdf: Chroot Validation Bypass
PKSA-mckv-s5hg-868k CVE-2026-55554 GHSA-wvh6-f5jh-8gw4
Affected version: <3.1.6
Reported by:
GitHub