LOW
Dompdf Project
CVE published 2026-07-28
CVE-2026-55555
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-28T20:17:26.867Z and has not been modified since then. The vulnerability affects Dompdf versions 3.15 and prior, allowing attackers to perform a File Existence Oracle attack through manipulation of the CSS @font-face directive. This could lead to enumeration of sensitive files on the server and pote [truncated]