CVE-2026-59943
Description
Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can supply unrestricted content for rendering by Dompdf they can utilize the SVG rendering functionality to leak filesystem information when rendering PDF files using image references within a data-URI encoded SVG document. Using an element inside a data-URI embedded SVG, an attacker can attempt to embed other files via the href or xlink:href attributes. When processing a file that does not exist (e.g. file:///DOESNOTEXIST), dompdf behaves differently than it does when accessing a file or directory that actually exists on the filesystem. This issue has been fixed in version 3.16.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
dompdf/dompdfPackagist | < 3.1.6 | 3.1.6 |
Affected products
2Patches
Vulnerability mechanics
References
4- github.com/dompdf/dompdf/commit/6a58996865db05d8fede748507e50ac4b8c5bfd0nvdPatchWEB
- github.com/dompdf/dompdf/security/advisories/GHSA-j8qw-6jw8-r297nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-j8qw-6jw8-r297ghsaADVISORY
- github.com/dompdf/dompdf/releases/tag/v3.1.6nvdRelease NotesWEB
News mentions
1- Dompdf: Four Vulnerabilities Disclosed Together Affecting Versions 3.15 and PriorVypr Intelligence · Jul 29, 2026