Information disclosure in Dompdf - CVE-2026-59943

 

Information disclosure in Dompdf - CVE-2026-59943

Published: July 20, 2026


Vulnerability identifier: #VU138587
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-59943
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: dompdf
Affected software:
Dompdf

Detailed vulnerability description

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in embedded SVG image handling when rendering documents containing crafted SVG content. A remote attacker can embed references to filesystem paths in an SVG image to disclose sensitive information.

The issue can reveal the existence of files and directories on the underlying filesystem.


How to mitigate CVE-2026-59943

Install security update from vendor's website.

Sources