dompdf是dompdf团队开源的一个 HTML 到 PDF 的转换器。 dompdf 3.16之前版本存在资源管理错误漏洞,该漏洞源于接受BMP图像时仅依据声明的头部尺寸生成PNG,未限制宽高,导致通过GD分配完整像素画布,造成内存放大,可能导致拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56722 | 6.3 MEDIUM | Dompdf: Local file read due to improper file path validation in SVG images encoded as data |
| CVE-2026-59942 | 6.3 MEDIUM | Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps |
| CVE-2026-59943 | 6.3 MEDIUM | Dompdf: Embedded SVG images can leak existence of files and directories within the filesys |
| CVE-2026-55554 | 2.3 LOW | Dompdf: Chroot Validation Bypass |
| CVE-2026-55555 | 2.3 LOW | Dompdf: File existence oracle via font-face stylesheet declaration |
No comments yet