CVE-2026-56722: Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI
Description: An attacker, who controls the HTML input supplied to dompdf, can read arbitrary images from the server’s file system, bypassing the chroot restriction. The vulnerability is exploitable in the default configuration.
Exploitation conditions: An external user
Researcher: Nikita Sveshnikov (Positive Technologies)
References
- github.com/advisories/GHSA-cx96-42px-69fm
- github.com/dompdf/dompdf/commit/6a58996865db05d8fede748507e50ac4b8c5bfd0
- github.com/dompdf/dompdf/commit/bf7b02f642e26007dedc5a22b3d6e15f9931120a
- github.com/dompdf/dompdf/releases/tag/v3.1.6
- github.com/dompdf/dompdf/security/advisories/GHSA-cx96-42px-69fm
- nvd.nist.gov/vuln/detail/CVE-2026-56722
Code Behaviors & Features
Detect and mitigate CVE-2026-56722 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →