dompdf是dompdf团队开源的一个 HTML 到 PDF 的转换器。 dompdf 3.15及之前版本存在侧信道信息泄露漏洞,该漏洞源于通过CSS @font-face指令操纵,攻击者可利用文件存在性差异触发PHP内存耗尽,从而枚举服务器敏感文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56722 | 6.3 MEDIUM | Dompdf: Local file read due to improper file path validation in SVG images encoded as data |
| CVE-2026-59941 | 6.3 MEDIUM | Dompdf: Uncontrolled resource consumption based on declared BMP dimensions |
| CVE-2026-59942 | 6.3 MEDIUM | Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps |
| CVE-2026-59943 | 6.3 MEDIUM | Dompdf: Embedded SVG images can leak existence of files and directories within the filesys |
| CVE-2026-55554 | 2.3 LOW | Dompdf: Chroot Validation Bypass |
No comments yet