Allocation of Resources Without Limits or Throttling in Dompdf - CVE-2026-55555

 

Allocation of Resources Without Limits or Throttling in Dompdf - CVE-2026-55555

Published: July 20, 2026


Vulnerability identifier: #VU138600
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-55555
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: dompdf
Affected software:
Dompdf

Detailed vulnerability description

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to allocation of resources without limits or throttling in the CSS @font-face handling in Dompdf when processing user-supplied HTML that references local files through the file:// protocol repeatedly. A remote attacker can submit specially crafted HTML content to disclose sensitive information.

Exploitation requires the ability to supply unrestricted or unsanitized HTML content, and the observable behavior differs depending on whether the referenced local file exists.


How to mitigate CVE-2026-55555

Install security update from vendor's website.

Sources