| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| dompdf-3.1.6.zip | 2026-07-23 | 4.1 MB | |
| Dompdf 3.1.6 source code.tar.gz | 2026-07-20 | 3.8 MB | |
| Dompdf 3.1.6 source code.zip | 2026-07-20 | 3.8 MB | |
| README.md | 2026-07-20 | 1.9 kB | |
| Totals: 4 Items | 11.7 MB | 57 | |
This release addresses the following announced vulnerabilities:
| Vulnerability | References | Type | Severity |
|---|---|---|---|
| Chroot Validation Bypass | GHSA-wvh6-f5jh-8gw4 | Validation Bypass | Moderate |
| File existence oracle via font-face stylesheet declaration | GHSA-7x2p-4jvh-6384 | Information Disclosure | Moderate |
| Local file read due to improper file path validation in SVG images encoded as data-URI | GHSA-cx96-42px-69fm | Information Disclosure | Moderate |
| Embedded SVG images can leak existence of files and directories within the filesystem | GHSA-j8qw-6jw8-r297 | Information Disclosure | Moderate |
| Denial of Service via Resource Exhaustion using Oversized Image Bitmaps | GHSA-f5gf-2cj8-52g2 | Denial of Service | Moderate |
| Uncontrolled resource consumption based on declared BMP dimensions | GHSA-8hg6-c449-896m | Denial of Service | Moderate |
Review the Securing Dompdf wiki document for guidance on steps you can take to mitigate your installation against potential exploit.
Full Changelog: https://github.com/dompdf/dompdf/compare/v3.1.5...v3.1.6