{"id":"CVE-2026-59943","aliases":["GHSA-j8qw-6jw8-r297"],"url":"https://o3.security/vulnerability/CVE-2026-59943","summary":"Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem","details":"Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can supply unrestricted content for rendering by Dompdf they can utilize the SVG rendering functionality to leak filesystem information when rendering PDF files using image references within a data-URI encoded SVG document. Using an <image> element inside a data-URI embedded SVG, an attacker can attempt to embed other files via the href or xlink:href attributes. When processing a file that does not exist (e.g. file:///DOESNOTEXIST), dompdf behaves differently than it does when accessing a file or directory that actually exists on the filesystem. This issue has been fixed in version 3.16.","published":"2026-07-28T20:19:22.746Z","modified":"2026-08-12T03:51:43.801420338Z","cvss":null,"epss":{"score":0.00299,"percentile":0.22246,"asOf":"2026-09-06"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"dompdf/dompdf","fixedVersion":"3.1.6"}],"fix":{"url":"https://github.com/dompdf/dompdf/commit/6a58996865db05d8fede748507e50ac4b8c5bfd0","label":"dompdf/dompdf@6a58996"},"references":[{"type":"WEB","url":"https://github.com/dompdf/dompdf/releases/tag/v3.1.6"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59943.json"},{"type":"ADVISORY","url":"https://github.com/dompdf/dompdf/security/advisories/GHSA-j8qw-6jw8-r297"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59943"},{"type":"FIX","url":"https://github.com/dompdf/dompdf/commit/6a58996865db05d8fede748507e50ac4b8c5bfd0"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:43.801420338Z"}}