Information disclosure in Dompdf - CVE-2026-59943
Published: July 20, 2026
Dompdf
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in embedded SVG image handling when rendering documents containing crafted SVG content. A remote attacker can embed references to filesystem paths in an SVG image to disclose sensitive information.
The issue can reveal the existence of files and directories on the underlying filesystem.