What is CVE-2026-55555?
CVE-2026-55555 is a File Existence Oracle vulnerability in Dompdf, a PHP HTML-to-PDF converter, affecting versions 3.15 and prior. An attacker can exploit this by providing malicious HTML that repeatedly references local files via the file:// protocol in CSS @font-face directives, triggering a PHP memory issue. It is recommended to update Dompdf to the latest version.
Azərbaycanca: CVE-2026-55555, PHP üçün HTML-PDF çeviricisi Dompdf-in 3.15 və əvvəlki versiyalarında aşkarlanmış File Existence Oracle zəifliyidir. Zərərli şəxs CSS @font-face direktivi vasitəsilə file:// protokolu ilə lokal fayllara təkrar müraciət edərək PHP yaddaş problemindən istifadə edə bilər. Bu səbəbdən Dompdf-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which versions of Dompdf are affected by CVE-2026-55555?
This vulnerability affects Dompdf versions 3.15 and prior.
How is an attack exploiting CVE-2026-55555 carried out?
An attacker provides malicious HTML that repeatedly references local files via the file:// protocol in CSS @font-face directives, exploiting a PHP memory issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.