Information Disclosure Vulnerability in Dompdf by Dompdf
CVE-2026-59943

6.3MEDIUM

Key Information:

Vendor

DomPDF

Status
Vendor
CVE Published:
28 July 2026

What is CVE-2026-59943?

Dompdf is an HTML to PDF converter for PHP that has a vulnerability allowing malicious actors to exploit the SVG rendering feature. In versions 3.15 and earlier, attackers can supply uncontrolled content to Dompdf, enabling them to leak sensitive filesystem information. By embedding an element in a data-URI encoded SVG and manipulating the href or xlink:href attributes, attackers may attempt to access non-existent files in a way that reveals differences in response behavior. This significant issue has been addressed in version 3.16.

Affected Version(s)

dompdf < 3.1.6

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.