Information Disclosure Vulnerability in Dompdf by Dompdf
CVE-2026-59943
6.3MEDIUM
What is CVE-2026-59943?
Dompdf is an HTML to PDF converter for PHP that has a vulnerability allowing malicious actors to exploit the SVG rendering feature. In versions 3.15 and earlier, attackers can supply uncontrolled content to Dompdf, enabling them to leak sensitive filesystem information. By embedding an element in a data-URI encoded SVG and manipulating the href or xlink:href attributes, attackers may attempt to access non-existent files in a way that reveals differences in response behavior. This significant issue has been addressed in version 3.16.
Affected Version(s)
dompdf < 3.1.6
