SB20260720187 - Multiple vulnerabilities in Dompdf
Published: July 20, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 6 vulnerabilities.
1) Resource exhaustion (CVE-ID: CVE-2026-59941)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the BMP image processing component when parsing BMP files with declared dimensions. A remote attacker can supply a specially crafted BMP file to cause a denial of service.
2) Information disclosure (CVE-ID: CVE-2026-59943)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in embedded SVG image handling when rendering documents containing crafted SVG content. A remote attacker can embed references to filesystem paths in an SVG image to disclose sensitive information.
The issue can reveal the existence of files and directories on the underlying filesystem.
3) Resource exhaustion (CVE-ID: CVE-2026-59942)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in image bitmap processing when parsing oversized image bitmaps. A remote attacker can supply a specially crafted oversized image bitmap to cause a denial of service.
4) Input validation error (CVE-ID: CVE-2026-56722)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper input validation in SVG image handling when processing SVG images encoded as data-URI. A remote attacker can supply a specially crafted SVG image to disclose sensitive information.
5) Input validation error (CVE-ID: CVE-2026-55554)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper input validation in the validateLocalUri() method when processing attacker-controlled document paths or resources. A remote attacker can supply crafted HTML containing local file references to disclose sensitive information.
Exploitation requires control over a portion of the rendered HTML.
6) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-55555)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to allocation of resources without limits or throttling in the CSS @font-face handling in Dompdf when processing user-supplied HTML that references local files through the file:// protocol repeatedly. A remote attacker can submit specially crafted HTML content to disclose sensitive information.
Exploitation requires the ability to supply unrestricted or unsanitized HTML content, and the observable behavior differs depending on whether the referenced local file exists.
Remediation
Install update from vendor's website.
References
- https://github.com/dompdf/dompdf/security/advisories/GHSA-8hg6-c449-896m
- https://github.com/dompdf/dompdf/security/advisories/GHSA-j8qw-6jw8-r297
- https://github.com/dompdf/dompdf/security/advisories/GHSA-f5gf-2cj8-52g2
- https://github.com/dompdf/dompdf/security/advisories/GHSA-cx96-42px-69fm
- https://github.com/dompdf/dompdf/security/advisories/GHSA-wvh6-f5jh-8gw4
- https://github.com/dompdf/dompdf/security/advisories/GHSA-7x2p-4jvh-6384