Threat Advisory

Dompdf Chroot Validation Bypass Allows File Read

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in dompdf/dompdf, affecting version 3.1.0 and later. The overall risk/impact is considered high due to potential exploitation of these vulnerabilities.

CVE-2026-55554: A chroot validation bypass vulnerability exists in the Dompdf library, allowing an attacker to potentially execute arbitrary code on the system. This can be exploited by manipulating file paths and using the library's functionality to access sensitive areas of the filesystem.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in dompdf/dompdf, affecting version 3.1.0 and later. The overall risk/impact is considered high due to potential exploitation of these vulnerabilities.

CVE-2026-55554: A chroot validation bypass vulnerability exists in the Dompdf library, allowing an attacker to potentially execute arbitrary code on the system. This can be exploited by manipulating file paths and using the library's functionality to access sensitive areas of the filesystem.[emaillocker id="1283"]

CVE-2026-55555: A file existence oracle via font-face stylesheet declaration vulnerability has been identified in the Dompdf library. An attacker can use this vulnerability to determine the existence of files on the system, potentially leading to further exploitation.

CVE-2026-56722: A local file read vulnerability exists due to improper file path validation in SVG images encoded as data-URI. This allows an attacker to read sensitive files on the system by manipulating image paths and using the library's functionality to access them.

CVE-2026-59941: An uncontrolled resource consumption vulnerability has been identified based on declared BMP dimensions in the Dompdf library. An attacker can use this vulnerability to cause a denial of service by consuming excessive system resources.

CVE-2026-59942: A denial of service (DoS) vulnerability exists due to resource exhaustion using oversized image bitmaps in the Dompdf library. This allows an attacker to consume excessive system resources, potentially leading to a denial of service.

CVE-2026-59943: An embedded SVG images can leak existence of files and directories within the filesystem vulnerability has been identified in the Dompdf library. An attacker can use this vulnerability to determine the existence of sensitive files on the system, potentially leading to further exploitation.

These vulnerabilities collectively present a significant risk to systems using the dompdf/dompdf library.

RECOMMENDATION:

We recommend you to update dompdf to the 3.1.6 version.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu