🛡️ CVE-2026-55554 — dompdf

🟠 CVSS 7.5 — High ⚠️ Exploit Public CWE-20 NVD
7.5
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Dompdf: Chroot Validation Bypass ### Summary The chroot check for local files uses a prefix string check to enforce chroot boundaries. The simple string comparison it performs allows paths like /var/www/root_secret/file.html when chroot is /var/www/root. This allows attacker-controlled document paths/resources to bypass intended local file restrictions. ### Details The `validateLocalUri()` method is used to check if a local file is within an allowed chroot directory. After normalization with `realpath()`, this check is performed with a `strpos()` comparison: ``` public function validateLocalUri(string $uri) { ... $realfile = realpath(str_replace("file://", "", $uri)); ... foreach ($dirs as $chrootPath) { $chrootPath = realpath($chrootPath); if ($chrootPath !== false && strpos($realfile, $chrootPath) === 0) { $chrootValid = true; ``` Due to the normalization, the `$chrootPath` string does not have a terminating directory separator (`/`) appended. Because of this, the `strpos()` check only validates that `$chrootPath` is a _prefix_ of `$realfile`. This allows access to folders with similar names that fall outside of the defined chroot restrictions. For example, a chroot setting of `/var/www/` would be normalized to `/var/www`, removing the trailing `/`. During `strpos()`, a `$chrootPath` of `/var/www` will also match a `$realfile` starting with `/var/www2`, `/var/www-admin`, or `/var/www_backup`, despite these being different directories. ### PoC With a directory structure similar to: ``` /home/dompdf/ |--> web/ |--> pdf.php |--> cat0.jpg |--> web-admin/ |--> cat1.jpg ``` And web-accessible Dompdf functionality similar to the following (poc.html): ``` setChroot(['/home/dompdf/web/']); $dompdf = new Dompdf($options); $dompdf->loadHtml($_POST['html']); $dompdf->render(); $dompdf->stream(); ?> ``` A malicious actor can exploit the vulnerability with the following script: ``` $html = <<<HTML

within chroot

outside of chroot

HTML; $url = 'http://example.com/poc.php'; $data = ['html' => $html]; $headers = ["Content-type: application/x-www-form-urlencoded"]; // use key 'http' even if you send the request to https://... $options = [ 'http' => [ 'header' => $headers, 'method' => 'POST', 'content' => http_build_query($data), 'ignore_errors' => true, ], ]; $context = stream_context_create($options); $response = file_get_contents($url, false, $context); ``` When the PDF is generated, both `jpg` files are loaded successfully despite the `cat1.jpg` file being outside of the allowed chroot. ### Impact An attacker that controls a portion of the rendered HTML could leverage this vulnerability to bypass chroot restrictions and access potentially sensitive files from outside of the allowed directories.

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality high, integrity none, availability none.

Weakness class

CVE-2026-55554 is classified as CWE-20: Improper Input Validation. The application accepts input without checking that it has the expected form, so malformed values reach code that assumes they are well formed.

Affected software

CVE-2026-55554 is recorded against 2 packages.

  • dompdf (fixed in 3.1.6)
  • dompdf/dompdf (fixed in 3.1.6)

Timeline and source

Published on 28 July 2026 and last revised on 5 August 2026. A public exploit is known to exist, which raises the urgency of patching considerably. Record sourced from NVD.

References

github.com
github.com
github.com

Details

Severity HIGH
CVSS Score 7.5
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE CWE-20
Public Exploit ⚠️ Yes
Source NVD
Published 2026-07-28
Updated 2026-08-12
Modified 2026-08-05
Fix URL N/A

Affected Packages

Software From version Fixed in
dompdf 3.1.6
dompdf/dompdf 3.1.6

Exploit Protection

Are you running dompdf?

CVE-2026-55554 carries CVSS 7.5 High rating and a public exploit already exists. BotEraser checks your installation against this and other known CVE records, and blocks IPs associated with exploit activity.

Check My Site For CVE-2026-55554 →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.