Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem (CVE-2026-59943)
Dompdf versions prior to 3.1.6 contain a vulnerability where embedded SVG images using data-URI encoding can leak information about the existence of files and directories on the backend filesystem. This occurs because the SVG <image> element referencing local files behaves differently when the file exists versus when it does not, allowing an attacker to infer filesystem structure. The vulnerability does not disclose file contents but confirms presence or absence of files or directories.
AI Analysis
Technical Summary
The vulnerability in dompdf/dompdf (CVE-2026-59943) arises from how the library processes embedded SVG images with <image> elements referencing local files via file:// URIs inside data-URI encoded SVG documents. When rendering PDFs, dompdf differentiates between existing and non-existing files by generating distinct behaviors and warnings, which an attacker can observe to confirm the existence of files or directories on the server filesystem. This information leak is due to error messages and rendering differences triggered by file_get_contents and getimagesize calls within the SVG rendering code. The issue affects all dompdf versions before 3.1.6.
Potential Impact
An attacker able to supply unrestricted SVG content for rendering can confirm the existence of arbitrary files or directories on the server hosting dompdf. This information disclosure does not reveal file contents but can aid in further targeted attacks by mapping the filesystem structure. There is no indication of remote code execution or privilege escalation from this vulnerability alone.
Mitigation Recommendations
A fix is available in dompdf version 3.1.6 and later. Users should upgrade to version 3.1.6 or newer to remediate this vulnerability. Until upgraded, restrict or sanitize any user-supplied SVG content to prevent embedding of file:// URIs. No vendor advisory was provided, so check the official dompdf release notes or repository for patch confirmation.
Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem (CVE-2026-59943)
Description
Dompdf versions prior to 3.1.6 contain a vulnerability where embedded SVG images using data-URI encoding can leak information about the existence of files and directories on the backend filesystem. This occurs because the SVG <image> element referencing local files behaves differently when the file exists versus when it does not, allowing an attacker to infer filesystem structure. The vulnerability does not disclose file contents but confirms presence or absence of files or directories.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in dompdf/dompdf (CVE-2026-59943) arises from how the library processes embedded SVG images with <image> elements referencing local files via file:// URIs inside data-URI encoded SVG documents. When rendering PDFs, dompdf differentiates between existing and non-existing files by generating distinct behaviors and warnings, which an attacker can observe to confirm the existence of files or directories on the server filesystem. This information leak is due to error messages and rendering differences triggered by file_get_contents and getimagesize calls within the SVG rendering code. The issue affects all dompdf versions before 3.1.6.
Potential Impact
An attacker able to supply unrestricted SVG content for rendering can confirm the existence of arbitrary files or directories on the server hosting dompdf. This information disclosure does not reveal file contents but can aid in further targeted attacks by mapping the filesystem structure. There is no indication of remote code execution or privilege escalation from this vulnerability alone.
Mitigation Recommendations
A fix is available in dompdf version 3.1.6 and later. Users should upgrade to version 3.1.6 or newer to remediate this vulnerability. Until upgraded, restrict or sanitize any user-supplied SVG content to prevent embedding of file:// URIs. No vendor advisory was provided, so check the official dompdf release notes or repository for patch confirmation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-j8qw-6jw8-r297
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-59943"]
- Ecosystems
- ["Packagist"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6a616bd09c2644c7f80dbefe
Added to database: 07/23/2026, 01:18:08 UTC
Last enriched: 07/23/2026, 01:23:05 UTC
Last updated: 09/05/2026, 05:49:46 UTC
Views: 103
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.