#1145374 icinga-php-thirdparty: please update bundled dompdf (CVE-2026-56722, CVE-2026-55554)

Package:
icinga-php-thirdparty
Source:
icinga-php-thirdparty
Submitter:
Gajendra Nath Soren
Date:
2026-08-24 15:37:02 UTC
Severity:
normal
Tags:
#1145374#5
Date:
2026-08-24 13:53:00 UTC
From:
To:
icinga-php-thirdparty vendors dompdf 3.1.5 at:
  vendor/dompdf/dompdf/

This version is affected by two vulnerabilities fixed in dompdf 3.1.6:

  CVE-2026-56722: local file read via SVG images embedded as data-URIs
                  (path validation bypass)
  CVE-2026-55554: chroot validation bypass via path traversal

Please update the bundled dompdf to 3.1.6 or later.

The bundled version was confirmed by reading:
  vendor/dompdf/dompdf/version (contains: 3.1.5)

Found by: Attack of the Clones GSoC 2026 pipeline
  (salsa.debian.org/rouca/gsoc2026)

Gajendra

#1145374#10
Date:
2026-08-24 15:23:51 UTC
From:
To:
Upstream needs to update their composer config.

Kind Regards,

Bas