dompdf/dompdf vulnerabilities
CVEs whose affected-version data names the dompdf/dompdf package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
6 CVEsRSS
CVE-2026-59941MediumPoCDompdf: Uncontrolled resource consumption based on declared BMP dimensions
Dompdf: Uncontrolled resource consumption based on declared BMP dimensions
▾ Twilightdompdf · dompdf/dompdfEPSS 0.51%via GHSA
CVE-2026-59942MediumDompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
▾ Sunlitdompdf · dompdf/dompdfEPSS 0.75%via GHSA
CVE-2026-59943MediumDompdf: Embedded SVG images can leak existence of files and directories within the filesystem
Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem
▾ Sunlitdompdf · dompdf/dompdfEPSS 0.30%via GHSA
CVE-2026-55554LowDompdf: Chroot Validation Bypass
Dompdf: Chroot Validation Bypass
▾ Sunlitdompdf · dompdf/dompdfEPSS 0.33%via GHSA
CVE-2026-55555LowDompdf: File existence oracle via font-face stylesheet declaration
Dompdf: File existence oracle via font-face stylesheet declaration
▾ Sunlitdompdf · dompdf/dompdfEPSS 0.35%via GHSA
CVE-2026-56722MediumDompdf: Local file read due to improper file path validation in SVG images encoded as data-URI
Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI
▾ Sunlitdompdf · dompdf/dompdfEPSS 0.33%via GHSA