dompdf has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was July 2026 with 6. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- —
- Publish → KEV
- —
- Last 90 days
- 6 prev 0
Worst active — by depth score
CVE-2026-59941MediumDompdf: Uncontrolled resource consumption based on declared BMP dimensions40CVE-2026-59943MediumDompdf: Embedded SVG images can leak existence of files and directories within the filesystem28CVE-2026-59942MediumDompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps28CVE-2026-56722MediumDompdf: Local file read due to improper file path validation in SVG images encoded as data-URI28CVE-2026-55555LowDompdf: File existence oracle via font-face stylesheet declaration14
dompdf vulnerabilities
CVEs affecting dompdf, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-59941MediumPoCDompdf: Uncontrolled resource consumption based on declared BMP dimensions
Dompdf: Uncontrolled resource consumption based on declared BMP dimensions
CVE-2026-59942MediumDompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
CVE-2026-59943MediumDompdf: Embedded SVG images can leak existence of files and directories within the filesystem
Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem
CVE-2026-55554LowDompdf: Chroot Validation Bypass
Dompdf: Chroot Validation Bypass
CVE-2026-55555LowDompdf: File existence oracle via font-face stylesheet declaration
Dompdf: File existence oracle via font-face stylesheet declaration
CVE-2026-56722MediumDompdf: Local file read due to improper file path validation in SVG images encoded as data-URI
Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI