[Pkg-nagios-devel] Bug#1145374: icinga-php-thirdparty: please update bundled dompdf (CVE-2026-56722, CVE-2026-55554)
Gajendra Nath Soren
gajendranath025 at gmail.com
Mon Aug 24 14:53:00 BST 2026
Package: icinga-php-thirdparty
Version: 1.0.0-1
Severity: important
Tags: security
X-Debbugs-Cc: team at security.debian.org, gajendranath025 at gmail.com
icinga-php-thirdparty vendors dompdf 3.1.5 at:
vendor/dompdf/dompdf/
This version is affected by two vulnerabilities fixed in dompdf 3.1.6:
CVE-2026-56722: local file read via SVG images embedded as data-URIs
(path validation bypass)
CVE-2026-55554: chroot validation bypass via path traversal
Please update the bundled dompdf to 3.1.6 or later.
The bundled version was confirmed by reading:
vendor/dompdf/dompdf/version (contains: 3.1.5)
Found by: Attack of the Clones GSoC 2026 pipeline
(salsa.debian.org/rouca/gsoc2026)
Gajendra
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/pkg-nagios-devel/attachments/20260824/463d2a7c/attachment.htm>
More information about the Pkg-nagios-devel
mailing list