Allocation of Resources Without Limits or Throttling in Dompdf - CVE-2026-55555
Published: July 20, 2026
Dompdf
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to allocation of resources without limits or throttling in the CSS @font-face handling in Dompdf when processing user-supplied HTML that references local files through the file:// protocol repeatedly. A remote attacker can submit specially crafted HTML content to disclose sensitive information.
Exploitation requires the ability to supply unrestricted or unsanitized HTML content, and the observable behavior differs depending on whether the referenced local file exists.