<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T11:46:37.717296+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-342427</id>
    <title>EUVD-2026-342427</title>
    <updated>2026-10-03T11:46:37.799089+00:00</updated>
    <content>EUVD-2026-342427</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-342427"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55554</id>
    <title>fkie_cve-2026-55554</title>
    <updated>2026-10-03T11:46:37.799132+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, the validateLocalUri() method enforces chroot boundaries with a strpos() prefix check after normalizing paths with  realpath() . Because normalization strips the trailing directory separator from  $chrootPath , the check only verifies that  $chrootPath  is a string prefix of $realfile, so a chroot of  /var/www  also matches sibling directories like /var/www2 , /var/www-admin, or /var/www_backup. An attacker who controls part of the rendered HTML could exploit this to escape the chroot and read sensitive files outside the allowed directory. This issue has been fixed in version 3.16.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-55554"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wvh6-f5jh-8gw4</id>
    <title>GHSA-wvh6-f5jh-8gw4 — Dompdf: Chroot Validation Bypass</title>
    <updated>2026-10-03T11:46:37.799170+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: dompdf/dompdf</p>
<p>### Summary
The chroot check for local files uses a prefix string check to enforce chroot boundaries. The simple string comparison it performs allows paths like /var/www/root_secret/file.html when chroot is /var/www/root.</p>
<p>This allows attacker-controlled document paths/resources to bypass intended local file restrictions.</p>
<p>### Details
The `validateLocalUri()` method is used to check if a local file is within an allowed chroot directory. After normalization with `realpath()`, this check is performed with a `strpos()` comparison:</p>
<p>```
    public function validateLocalUri(string $uri)
    {
        ...
        $realfile = realpath(str_replace("file://", "", $uri));
        ...
        foreach ($dirs as $chrootPath) {
            $chrootPath = realpath($chrootPath);
            if ($chrootPath !== false &amp;&amp; strpos($realfile, $chrootPath) === 0) {
                $chrootValid = true;
```</p>
<p>Due to the normalization, the `$chrootPath` string does not have a terminating directory separator (`/`) appended. Because of this, the `strpos()` check only validates that `$chrootPath` is a _prefix_ of  `$realfile`. This allows access to folders with similar names that fall outside of the defined chroot restrictions.</p>
<p>For example, a chroot setting of `/var/www/` would be normalized to `/var/www`, removing the trailing `/`. During `strpos()`, a `$chrootPath` of `/var/www` will also match a `$realfile` starting with `/var/www2`, `/var/www-admin`, or `/var/www_backup`, despite these being differe…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wvh6-f5jh-8gw4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-55554</id>
    <title>UBUNTU-CVE-2026-55554</title>
    <updated>2026-10-03T11:46:37.799236+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: php-dompdf, Ubuntu:Pro:18.04:LTS: php-dompdf, Ubuntu:20.04:LTS: php-dompdf, Ubuntu:22.04:LTS: php-dompdf</p>
<p>Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, the validateLocalUri() method enforces chroot boundaries with a strpos() prefix check after normalizing paths with  realpath() . Because normalization strips the trailing directory separator from  $chrootPath , the check only verifies that  $chrootPath  is a string prefix of $realfile, so a chroot of  /var/www  also matches sibling directories like /var/www2 , /var/www-admin, or /var/www_backup. An attacker who controls part of the rendered HTML could exploit this to escape the chroot and read sensitive files outside the allowed directory. This issue has been fixed in version 3.16.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-55554"/>
  </entry>
</feed>
