Executive brief
Dompdf is a popular PHP library used to convert HTML documents into PDF files. A security flaw allows an attacker to bypass directory restrictions and read sensitive image files from the server's filesystem by providing specially crafted HTML input. This could lead to the unauthorized exposure of private server data or user-uploaded images.
Technical details
Dompdf versions 3.1.5 and prior are vulnerable to a local file read vulnerability when processing SVG images delivered via data-URIs. The root cause is a double-processing flaw: Dompdf's initial validation pass fails to correctly resolve paths within data-URI encoded SVGs, and the subsequent rendering pass hands the SVG to 'php-svg-lib' with external references forced on. Because 'php-svg-lib' lacks knowledge of Dompdf's chroot restrictions and only blocks the 'phar://' scheme, it uses 'file_get_contents()' to read any referenced file path. An unauthenticated attacker who can provide HTML input to the library can exploit this to embed arbitrary local images into the generated PDF. The issue is fixed in version 3.1.6.
Affected products
- dompdf dompdf <= 3.1.5
Timeline
- 2026-07-20: advisory: GitHub Security Advisory GHSA-cx96-42px-69fm published
- 2026-07-20: patched: Version 3.1.6 released
- 2026-07-28: disclosed: CVE-2026-56722 published to NVD