icinga-php-thirdparty vendors dompdf 3.1.5 at:
vendor/dompdf/dompdf/
This version is affected by two vulnerabilities fixed in dompdf 3.1.6:
CVE-2026-56722: local file read via SVG images embedded as data-URIs
(path validation bypass)
CVE-2026-55554: chroot validation bypass via path traversal
Please update the bundled dompdf to 3.1.6 or later.
The bundled version was confirmed by reading:
vendor/dompdf/dompdf/version (contains: 3.1.5)
Found by: Attack of the Clones GSoC 2026 pipeline
(salsa.debian.org/rouca/gsoc2026)
Gajendra