[Git][security-tracker-team/security-tracker][master] Add new php-dompdf issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Jul 29 08:47:08 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
86b744c6 by Salvatore Bonaccorso at 2026-07-29T09:46:41+02:00
Add new php-dompdf issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -43,11 +43,18 @@ CVE-2026-62325 (goshs is a feature-rich single-binary file server for red teamer
 CVE-2026-5626 (The Survey Form Block plugin for WordPress is vulnerable to unauthoriz ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-59943 (Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior ...)
-	TODO: check
+	- php-dompdf <unfixed>
+	NOTE: https://github.com/dompdf/dompdf/security/advisories/GHSA-j8qw-6jw8-r297
+	NOTE: Fixed by: https://github.com/dompdf/dompdf/commit/6a58996865db05d8fede748507e50ac4b8c5bfd0 (v3.1.6)
 CVE-2026-59942 (Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior ar ...)
-	TODO: check
+	- php-dompdf <unfixed>
+	NOTE: https://github.com/dompdf/dompdf/security/advisories/GHSA-f5gf-2cj8-52g2
+	NOTE: Fixed by: https://github.com/dompdf/dompdf/commit/7c65e7bbeccf146b2409740405af73949ad129d0 (v3.1.6)
+	NOTE: Fixed by: https://github.com/dompdf/dompdf/commit/89164eaabe0bb50c462f0b24f740044ba5fb0f99 (v3.1.6)
 CVE-2026-59941 (Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior ac ...)
-	TODO: check
+	- php-dompdf <unfixed>
+	NOTE: https://github.com/dompdf/dompdf/security/advisories/GHSA-8hg6-c449-896m
+	NOTE: Fixed by: https://github.com/dompdf/dompdf/commit/7c65e7bbeccf146b2409740405af73949ad129d0 (v3.1.6)
 CVE-2026-59921 (Netty is an asynchronous, event-driven network application framework.  ...)
 	TODO: check
 CVE-2026-57511 (SuperPlane before 0.30.0 contains an SMTP header injection vulnerabili ...)
@@ -59,11 +66,17 @@ CVE-2026-56822 (Netty is an asynchronous, event-driven network application frame
 CVE-2026-56821 (Netty is an asynchronous, event-driven network application framework.  ...)
 	TODO: check
 CVE-2026-56722 (Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior ...)
-	TODO: check
+	- php-dompdf <unfixed>
+	NOTE: https://github.com/dompdf/dompdf/security/advisories/GHSA-cx96-42px-69fm
+	NOTE: Fixed by: https://github.com/dompdf/dompdf/commit/6a58996865db05d8fede748507e50ac4b8c5bfd0 (v3.1.6)
+	NOTE: Fixed by: https://github.com/dompdf/dompdf/commit/bf7b02f642e26007dedc5a22b3d6e15f9931120a (v3.1.6)
 CVE-2026-55555 (Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior ar ...)
-	TODO: check
+	- php-dompdf <unfixed>
+	NOTE: https://github.com/dompdf/dompdf/security/advisories/GHSA-7x2p-4jvh-6384
+	NOTE: Fixed by: https://github.com/dompdf/dompdf/commit/75c39a083bf7298044fb27399b4cc183054438b4 (v3.1.6)
 CVE-2026-55554 (Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior ...)
-	TODO: check
+	- php-dompdf <unfixed>
+	NOTE: https://github.com/dompdf/dompdf/security/advisories/GHSA-wvh6-f5jh-8gw4
 CVE-2026-55415 (datamodel-code-generator generates Pydantic v2 models, dataclasses, Ty ...)
 	TODO: check
 CVE-2026-55403 (datamodel-code-generator generates Python data models from schema defi ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/86b744c629788202e75810890df2c2cefe39b55e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/86b744c629788202e75810890df2c2cefe39b55e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260729/b4d8081a/attachment.htm>


More information about the debian-security-tracker-commits mailing list