CVE-2026-59943: Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem
If a malicious actor can supply unrestricted content for rendering by Dompdf they can utilize the SVG rendering functionality to leak filesystem information when rendering PDF files using image references within a data-URI encoded SVG document.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-59943 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →