{"id":"CVE-2026-59941","aliases":["GHSA-8hg6-c449-896m"],"url":"https://o3.security/vulnerability/CVE-2026-59941","summary":"Dompdf: Uncontrolled resource consumption based on declared BMP dimensions","details":"Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior accept a BMP image and generates a PDF-compatible PNG based only on its declared header dimensions and never bounds width × height before the image is converted through GD. A 58-byte BMP whose header declares e.g. 6000×6000 is accepted and later drives imagecreatetruecolor($width, $height) (and PHP's native BMP decoder) to allocate the full pixel canvas. A payload can fit in a single HTTP request: the BMP can be inlined as a data:image/bmp;base64,… URI inside attacker-controlled HTML, so no upload, no remote fetch, and no chroot-reachable file is required. I measured a 169-byte request driving a dompdf render to ~412 MB peak RSS and ~4.8 s of CPU/wall time, versus ~34 MB for an identically-sized benign request — roughly a 12× memory amplification per request, repeatable and unauthenticated. This issue has been fixed in version 3.16.","published":"2026-07-28T20:42:57.010Z","modified":"2026-08-12T03:51:13.617078172Z","cvss":null,"epss":{"score":0.00635,"percentile":0.47504,"asOf":"2026-08-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"dompdf/dompdf","fixedVersion":"3.1.6"}],"fix":{"url":"https://github.com/dompdf/dompdf/commit/7c65e7bbeccf146b2409740405af73949ad129d0","label":"dompdf/dompdf@7c65e7b"},"references":[{"type":"WEB","url":"https://github.com/dompdf/dompdf/releases/tag/v3.1.6"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59941.json"},{"type":"ADVISORY","url":"https://github.com/dompdf/dompdf/security/advisories/GHSA-8hg6-c449-896m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59941"},{"type":"FIX","url":"https://github.com/dompdf/dompdf/commit/7c65e7bbeccf146b2409740405af73949ad129d0"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:13.617078172Z"}}