What is CVE-2026-56722?
CVE-2026-56722 affects Dompdf versions 3.15 and prior, allowing an attacker to bypass file path restrictions by embedding a target path inside an SVG image delivered via a `data:` URI. Since dompdf processes the SVG twice without enforcing restrictions on the second pass, this leads to potential security issues. Users should upgrade to the latest version.
Azərbaycanca: CVE-2026-56722 Dompdf kitabxanasında aşkarlanıb və 3.15 və daha əvvəlki versiyalara təsir edir. Təcavüzkar xüsusi hazırlanmış SVG faylı vasitəsilə `data:` URI sxemindən istifadə edərək fayl yolunu gizlədə və məhdudiyyətləri keçə bilər. İstifadəçilərə ən son versiyaya yeniləmə tövsiyə olunur.
FAQ2
Which versions of Dompdf are affected by CVE-2026-56722?
This vulnerability affects Dompdf library versions 3.15 and prior.
How can an attacker bypass file path restrictions using CVE-2026-56722?
An attacker can hide the target file path by using a `data:` URI scheme via a specially crafted SVG file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.