dompdf是dompdf团队开源的一个 HTML 到 PDF 的转换器。 dompdf 3.1.6之前版本存在输入验证错误漏洞,该漏洞源于validateLocalUri()方法对chroot边界检查不足,由于路径规范化移除尾部斜杠导致前缀匹配绕过,允许攻击者读取允许目录外的敏感文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56722 | 6.3 MEDIUM | Dompdf: Local file read due to improper file path validation in SVG images encoded as data |
| CVE-2026-59941 | 6.3 MEDIUM | Dompdf: Uncontrolled resource consumption based on declared BMP dimensions |
| CVE-2026-59942 | 6.3 MEDIUM | Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps |
| CVE-2026-59943 | 6.3 MEDIUM | Dompdf: Embedded SVG images can leak existence of files and directories within the filesys |
| CVE-2026-55555 | 2.3 LOW | Dompdf: File existence oracle via font-face stylesheet declaration |
No comments yet