<div dir="ltr">Package: icinga-php-thirdparty<br>Version: 1.0.0-1<br>Severity: important<br>Tags: security<br>X-Debbugs-Cc: <a href="mailto:team@security.debian.org">team@security.debian.org</a>, <a href="mailto:gajendranath025@gmail.com">gajendranath025@gmail.com</a><br><br>icinga-php-thirdparty vendors dompdf 3.1.5 at:<br>  vendor/dompdf/dompdf/<br><br>This version is affected by two vulnerabilities fixed in dompdf 3.1.6:<br><br>  CVE-2026-56722: local file read via SVG images embedded as data-URIs<br>                  (path validation bypass)<br>  CVE-2026-55554: chroot validation bypass via path traversal<br><br>Please update the bundled dompdf to 3.1.6 or later.<br><br>The bundled version was confirmed by reading:<br>  vendor/dompdf/dompdf/version (contains: 3.1.5)<br><br>Found by: Attack of the Clones GSoC 2026 pipeline<br>  (<a href="http://salsa.debian.org/rouca/gsoc2026">salsa.debian.org/rouca/gsoc2026</a>)<br><br>Gajendra</div>