dompdf是dompdf团队开源的一个 HTML 到 PDF 的转换器。 dompdf 3.1.6之前版本存在信息泄露漏洞,该漏洞源于SVG渲染功能对文件访问处理不当,可能导致恶意攻击者利用data-URI编码的SVG文档泄露文件系统信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56722 | 6.3 MEDIUM | Dompdf: Local file read due to improper file path validation in SVG images encoded as data |
| CVE-2026-59941 | 6.3 MEDIUM | Dompdf: Uncontrolled resource consumption based on declared BMP dimensions |
| CVE-2026-59942 | 6.3 MEDIUM | Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps |
| CVE-2026-55554 | 2.3 LOW | Dompdf: Chroot Validation Bypass |
| CVE-2026-55555 | 2.3 LOW | Dompdf: File existence oracle via font-face stylesheet declaration |
No comments yet