<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 12:30:48 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-04278</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-04278</link>
      <description>bdu:2026-04278</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-04278</guid>
    </item>
    <item>
      <title>EUVD-2026-342352</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-342352</link>
      <description>EUVD-2026-342352</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-342352</guid>
    </item>
    <item>
      <title>fkie_cve-2026-56722</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-56722</link>
      <description>&lt;p&gt;Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, aAn attacker who controls the HTML input can bypass this restriction by embedding a target file path inside an SVG image delivered through a  data:  URI, because dompdf processes the SVG twice and the second pass does not enforce the same protections as the first. When rendering, dompdf hands the SVG to the separate  php-svg-lib  library with external references forced on, and that library has no knowledge of the chroot directory, blocks only the  phar://  scheme, and ultimately reads the referenced file with no path or protocol validation. This lets an external, unauthenticated attacker read arbitrary image files from the server&amp;#39;s file system in the default configuration. This issue has been fixed in version 3.16.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, aAn attacker who controls the HTML input can bypass this restriction by embedding a target file path inside an SVG image delivered through a  data:  URI, because dompdf processes the SVG twice and the second pass does not enforce the same protections as the first. When rendering, dompdf hands the SVG to the separate  php-svg-lib  library with external references forced on, and that library has no knowledge of the chroot directory, blocks only the  phar://  scheme, and ultimately reads the referenced file with no path or protocol validation. This lets an external, unauthenticated attacker read arbitrary image files from the server&amp;#39;s file system in the default configuration. This issue has been fixed in version 3.16.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-56722</guid>
    </item>
    <item>
      <title>GHSA-cx96-42px-69fm — Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cx96-42px-69fm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: dompdf/dompdf&lt;/p&gt;
&lt;p&gt;**Description:** An attacker, who controls the HTML input supplied to dompdf, can read arbitrary images from the server’s file system, bypassing the `chroot` restriction. The vulnerability is exploitable in the default configuration.
**Exploitation conditions:** An external user
**Researcher:** Nikita Sveshnikov (Positive Technologies)&lt;/p&gt;
&lt;p&gt;## Research
dompdf restricts access to local files using the `chroot` mechanism. By default, `chroot` is set to the root directory of dompdf (`Options.php:350-351`):&lt;/p&gt;
&lt;p&gt;_Listing 1. `chroot` settings_
```
$rootDir = realpath(__DIR__ . &amp;#34;/../&amp;#34;);
$this-&amp;gt;setChroot(array($rootDir));
// result: chroot = [&amp;#34;/path/to/vendor/dompdf/dompdf&amp;#34;]
```
When the HTML references a local file, `Options::validateLocalUri()` checks that the path resides within `сhroot`. A direct link to the file outside this directory is correctly blocked:&lt;/p&gt;
&lt;p&gt;_Listing 2. Blocking link_
```
&amp;lt;!-- BLOCKED: /tmp/ is outside chroot --&amp;gt;
&amp;lt;img src=&amp;#34;file:///tmp/secret.png&amp;#34;&amp;gt;
```
### How the protection is bypassed:
An attacker wraps the link to the target file in SVG format and delivers it via `data:` URI:&lt;/p&gt;
&lt;p&gt;_Listing 3. Wrapping link in SVG_
```
&amp;lt;img src=&amp;#34;data:image/svg+xml;base64,PHN2ZyB4bWxucz0i...&amp;#34;&amp;gt;
```
Inside the base64 payload is an SVG containing the `&amp;lt;image&amp;gt;` element that points to the target file:&lt;/p&gt;
&lt;p&gt;_Listing 4. Pointing to the target file_
```
&amp;lt;svg xmlns=&amp;#34;http://www.w3.org/2000/svg&amp;#34; xmlns:xlink=&amp;#34;http://www.w3.org/1999/xlink&amp;#34;
     width=&amp;#34;589&amp;#34; height=&amp;#34;415&amp;#34;&amp;gt;
  &amp;lt;image xlink:href=&amp;#34;/tmp/secret.png…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: dompdf/dompdf&lt;/p&gt;
&lt;p&gt;**Description:** An attacker, who controls the HTML input supplied to dompdf, can read arbitrary images from the server’s file system, bypassing the `chroot` restriction. The vulnerability is exploitable in the default configuration.
**Exploitation conditions:** An external user
**Researcher:** Nikita Sveshnikov (Positive Technologies)&lt;/p&gt;
&lt;p&gt;## Research
dompdf restricts access to local files using the `chroot` mechanism. By default, `chroot` is set to the root directory of dompdf (`Options.php:350-351`):&lt;/p&gt;
&lt;p&gt;_Listing 1. `chroot` settings_
```
$rootDir = realpath(__DIR__ . &amp;#34;/../&amp;#34;);
$this-&amp;gt;setChroot(array($rootDir));
// result: chroot = [&amp;#34;/path/to/vendor/dompdf/dompdf&amp;#34;]
```
When the HTML references a local file, `Options::validateLocalUri()` checks that the path resides within `сhroot`. A direct link to the file outside this directory is correctly blocked:&lt;/p&gt;
&lt;p&gt;_Listing 2. Blocking link_
```
&amp;lt;!-- BLOCKED: /tmp/ is outside chroot --&amp;gt;
&amp;lt;img src=&amp;#34;file:///tmp/secret.png&amp;#34;&amp;gt;
```
### How the protection is bypassed:
An attacker wraps the link to the target file in SVG format and delivers it via `data:` URI:&lt;/p&gt;
&lt;p&gt;_Listing 3. Wrapping link in SVG_
```
&amp;lt;img src=&amp;#34;data:image/svg+xml;base64,PHN2ZyB4bWxucz0i...&amp;#34;&amp;gt;
```
Inside the base64 payload is an SVG containing the `&amp;lt;image&amp;gt;` element that points to the target file:&lt;/p&gt;
&lt;p&gt;_Listing 4. Pointing to the target file_
```
&amp;lt;svg xmlns=&amp;#34;http://www.w3.org/2000/svg&amp;#34; xmlns:xlink=&amp;#34;http://www.w3.org/1999/xlink&amp;#34;
     width=&amp;#34;589&amp;#34; height=&amp;#34;415&amp;#34;&amp;gt;
  &amp;lt;image xlink:href=&amp;#34;/tmp/secret.png…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cx96-42px-69fm</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-56722</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-56722</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: php-dompdf, Ubuntu:Pro:18.04:LTS: php-dompdf, Ubuntu:20.04:LTS: php-dompdf, Ubuntu:22.04:LTS: php-dompdf&lt;/p&gt;
&lt;p&gt;Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, aAn attacker who controls the HTML input can bypass this restriction by embedding a target file path inside an SVG image delivered through a  data:  URI, because dompdf processes the SVG twice and the second pass does not enforce the same protections as the first. When rendering, dompdf hands the SVG to the separate  php-svg-lib  library with external references forced on, and that library has no knowledge of the chroot directory, blocks only the  phar://  scheme, and ultimately reads the referenced file with no path or protocol validation. This lets an external, unauthenticated attacker read arbitrary image files from the server&amp;#39;s file system in the default configuration. This issue has been fixed in version 3.16.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: php-dompdf, Ubuntu:Pro:18.04:LTS: php-dompdf, Ubuntu:20.04:LTS: php-dompdf, Ubuntu:22.04:LTS: php-dompdf&lt;/p&gt;
&lt;p&gt;Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, aAn attacker who controls the HTML input can bypass this restriction by embedding a target file path inside an SVG image delivered through a  data:  URI, because dompdf processes the SVG twice and the second pass does not enforce the same protections as the first. When rendering, dompdf hands the SVG to the separate  php-svg-lib  library with external references forced on, and that library has no knowledge of the chroot directory, blocks only the  phar://  scheme, and ultimately reads the referenced file with no path or protocol validation. This lets an external, unauthenticated attacker read arbitrary image files from the server&amp;#39;s file system in the default configuration. This issue has been fixed in version 3.16.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-56722</guid>
    </item>
  </channel>
</rss>
