LOW
dompdf
CVE published 2026-07-28
CVE-2026-55554
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-28T20:17:26.723Z and has not been modified since then. The NVD entry is currently Analyzed. Dompdf versions 3.15 and prior contain a path traversal issue in the validateLocalUri() method, allowing potential reading of sensitive files outside the intended directory. The issue has been fixed in versio [truncated]