SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-55555

HIGH · CVSS 7.5 EPSS 0.35% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-28 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

Versions of Dompdf prior to 3.16 are vulnerable to a File Existence Oracle attack, allowing attackers to exploit the CSS @font-face directive to cause PHP memory exhaustion. By manipulating HTML to reference local files, an attacker can enumerate sensitive files on the server, bypassing CHROOT restrictions. Organizations using vulnerable versions of Dompdf should prioritize updating to version 3.16 or later to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-55555
Severity
HIGH
CVSS
7.5
EPSS
0.35%
Oracle

Original NVD Description

Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a File Existence Oracle attack through the manipulation of the CSS @font-face directive. By providing malicious HTML that references local files via the file:// protocol repeatedly, an attacker can trigger PHP memory exhaustion. Because Dompdf behaves differently depending on whether a referenced local file exists (an existing file is processed repeatedly until it triggers an "Allowed memory size exhausted" crash, whereas a missing file fails fast or is ignored and never hits the memory limit), an attacker can use this observable discrepancy as an oracle to enumerate sensitive files on the server regardless of CHROOT restrictions. Exploitation requires the attacker to supply unrestricted or unsanitized HTML in a request that permits large data, plus a configuration where Dompdf's memory limit is low enough to be exhausted (with  $_dompdf_show_warnings=true  making the overflow easier to reach). This issue has been fixed in version 3.16.

Related CVEs

Other vulnerabilities affecting the same vendor(s)