PatchSiren

Dompdf Project CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Dompdf Project CVE published 2026-07-28

CVE-2026-55555

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-28T20:17:26.867Z and has not been modified since then. The vulnerability affects Dompdf versions 3.15 and prior, allowing attackers to perform a File Existence Oracle attack through manipulation of the CSS @font-face directive. This could lead to enumeration of sensitive files on the server and pote [truncated]