Package: icinga-php-thirdparty
Version: 1.0.0-1
Severity: important
Tags: security
X-Debbugs-Cc: [email protected], [email protected]

icinga-php-thirdparty vendors dompdf 3.1.5 at:
  vendor/dompdf/dompdf/

This version is affected by two vulnerabilities fixed in dompdf 3.1.6:

  CVE-2026-56722: local file read via SVG images embedded as data-URIs
                  (path validation bypass)
  CVE-2026-55554: chroot validation bypass via path traversal

Please update the bundled dompdf to 3.1.6 or later.

The bundled version was confirmed by reading:
  vendor/dompdf/dompdf/version (contains: 3.1.5)

Found by: Attack of the Clones GSoC 2026 pipeline
  (salsa.debian.org/rouca/gsoc2026)

Gajendra

Reply via email to