DEBIAN-CVE-2026-55554

Source
https://security-tracker.debian.org/tracker/CVE-2026-55554
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-55554.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-55554
Upstream
Published
2026-07-28T20:17:26.723Z
Modified
2026-07-29T09:00:16.315575350Z
Severity
  • 2.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, the validateLocalUri() method enforces chroot boundaries with a strpos() prefix check after normalizing paths with  realpath() . Because normalization strips the trailing directory separator from  $chrootPath , the check only verifies that  $chrootPath  is a string prefix of $realfile, so a chroot of  /var/www  also matches sibling directories like /var/www2 , /var/www-admin, or /var/www_backup. An attacker who controls part of the rendered HTML could exploit this to escape the chroot and read sensitive files outside the allowed directory. This issue has been fixed in version 3.16.

References

Affected packages

Debian:11 / php-dompdf

Package

Name
php-dompdf
Purl
pkg:deb/debian/php-dompdf?arch=source&distro=bullseye

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.6.2+dfsg-3.1
0.6.2+dfsg-3.1+deb11u1
0.6.2+dfsg-4
2.*
2.0.2+dfsg-1
2.0.2+dfsg-2
2.0.3+dfsg-1
2.0.3+dfsg-2
2.0.3+dfsg-3
2.0.3+dfsg-4
2.0.4+dfsg-1
2.0.4+dfsg-2
2.0.7+dfsg-1
3.*
3.0.0+dfsg-1
3.0.0+dfsg-2
3.0.1+dfsg-1
3.0.2+dfsg-1
3.1.0+dfsg-1
3.1.4+dfsg-1
3.1.4+dfsg-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-55554.json"

Debian:12 / php-dompdf

Package

Name
php-dompdf
Purl
pkg:deb/debian/php-dompdf?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.0.3+dfsg-1
2.0.3+dfsg-1+deb12u1
2.0.3+dfsg-2
2.0.3+dfsg-3
2.0.3+dfsg-4
2.0.4+dfsg-1
2.0.4+dfsg-2
2.0.7+dfsg-1
3.*
3.0.0+dfsg-1
3.0.0+dfsg-2
3.0.1+dfsg-1
3.0.2+dfsg-1
3.1.0+dfsg-1
3.1.4+dfsg-1
3.1.4+dfsg-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-55554.json"