PatchSiren

dompdf CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW dompdf CVE published 2026-07-28

CVE-2026-55554

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-28T20:17:26.723Z and has not been modified since then. The NVD entry is currently Analyzed. Dompdf versions 3.15 and prior contain a path traversal issue in the validateLocalUri() method, allowing potential reading of sensitive files outside the intended directory. The issue has been fixed in versio [truncated]