VDB

CVE-2026-59943

CVE-2026-59943 PUBLISHED CVSS 6.3 MEDIUM

Reported by GitHub_M · Published July 28, 2026

Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can supply unrestricted content for rendering by Dompdf they can utilize the SVG rendering functionality to leak filesystem information when rendering PDF files using image references within a data-URI encoded SVG document. Using an <image> element inside a data-URI embedded SVG, an attacker can attempt to embed other files via the href or xlink:href attributes. When processing a file that does not exist (e.g. file:///DOESNOTEXIST), dompdf behaves differently than it does when accessing a file or directory that actually exists on the filesystem. This issue has been fixed in version 3.16.

Risk Scores

CVSS 4.0
6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
dompdfdompdf< 3.1.6
dompdfdompdf0
dompdfdompdf< 3.1.6, < 3.1.6, < 3.1.6

Timeline

  • Jul 22, 2026 CVE Published
  • Jul 29, 2026 Coalition ESS Score
  • Jul 29, 2026 Security Advisory
  • Jul 29, 2026 CVE Updated
  • Aug 7, 2026 EPSS Score
  • Aug 24, 2026 EPSS Score
  • Aug 29, 2026 EPSS Score
  • Sep 4, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 15, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›