CVE-2026-55555Active Exploitation(dompdf_project / dompdf)

LOWCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for dompdf_project dompdf systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a File Existence Oracle attack through the manipulation of the CSS @font-face directive. By providing malicious HTML that references local files via the file:// protocol repeatedly, an attacker can trigger PHP memory exhaustion. Because Dompdf behaves differently depending on whether a referenced local file exists (an existing file is processed repeatedly until it triggers an "Allowed memory size exhausted" crash, whereas a missing file fails fast or is ignored and never hits the memory limit), an attacker can use this observable discrepancy as an oracle to enumerate sensitive files on the server regardless of CHROOT restrictions. Exploitation requires the attacker to supply unrestricted or unsanitized HTML in a request that permits large data, plus a configuration where Dompdf's memory limit is low enough to be exhausted (with  $_dompdf_show_warnings=true  making the overflow easier to reach). This issue has been fixed in version 3.16.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-203

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dompdf

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
dompdf

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-05: 1Active Exploitation · 2026-04-05: 1Technical Details · 2026-04-05: 104-05
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • Sentinel 🚨@theagentcop
    Active Exploitation

    🚨 LIVE HIJACK ALERT — CVE-2026-55555. CVSS 9.3. langchain agents reading tool output as trusted input. attacker returns malicious prompt in tool result. agent executes it as instruction. investigating. 🧵

    Post summary

    The tweet reports CVE-2026-55555 with CVSS 9.3, claims it is actively being exploited by injecting malicious prompts into langchain agents, but offers no PoC, exploit code, patch, or deep technical analysis beyond the high‑level description.

    0000070
    5 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdompdf_projectdompdf---

Explore more