Executive brief
Dompdf is a PHP library used to convert HTML documents into PDF files. A security flaw allows an attacker to determine if specific sensitive files exist on the server by sending specially crafted HTML that triggers a memory crash only when a file is present. This can be used to map out a server's internal file structure or confirm the presence of configuration files and security keys, potentially aiding further attacks.
Technical details
Dompdf (versions 3.1.5 and prior) is vulnerable to a File Existence Oracle attack through the manipulation of the CSS @font-face directive. By providing malicious HTML that references local files via the file:// protocol repeatedly, an attacker can trigger PHP memory exhaustion. The vulnerability stems from an observable discrepancy: if a referenced local file exists, Dompdf attempts to process the resource multiple times until it hits the 'Allowed memory size exhausted' limit; if the file does not exist, it fails fast without exhausting memory. This allows an attacker to bypass CHROOT restrictions to enumerate sensitive files. Exploitation requires the ability to submit unsanitized HTML to an endpoint with a low enough PHP memory limit to be triggered. The issue is fixed in version 3.1.6.
Affected products
- dompdf dompdf <= 3.1.5
Timeline
- 2026-07-20: patched: Fixed in version 3.1.6
- 2026-07-20: advisory: GitHub Security Advisory GHSA-7x2p-4jvh-6384 published
- 2026-07-28: disclosed: CVE-2026-55555 published to NVD