[Pkg-nagios-devel] Bug#1145374: icinga-php-thirdparty: please update bundled dompdf (CVE-2026-56722, CVE-2026-55554)

Gajendra Nath Soren gajendranath025 at gmail.com
Mon Aug 24 14:53:00 BST 2026


Package: icinga-php-thirdparty
Version: 1.0.0-1
Severity: important
Tags: security
X-Debbugs-Cc: team at security.debian.org, gajendranath025 at gmail.com

icinga-php-thirdparty vendors dompdf 3.1.5 at:
  vendor/dompdf/dompdf/

This version is affected by two vulnerabilities fixed in dompdf 3.1.6:

  CVE-2026-56722: local file read via SVG images embedded as data-URIs
                  (path validation bypass)
  CVE-2026-55554: chroot validation bypass via path traversal

Please update the bundled dompdf to 3.1.6 or later.

The bundled version was confirmed by reading:
  vendor/dompdf/dompdf/version (contains: 3.1.5)

Found by: Attack of the Clones GSoC 2026 pipeline
  (salsa.debian.org/rouca/gsoc2026)

Gajendra
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/pkg-nagios-devel/attachments/20260824/463d2a7c/attachment.htm>


More information about the Pkg-nagios-devel mailing list