Skip to content

Bump dompdf/dompdf from 3.1.0 to 3.1.6#17

Open
dependabot[bot] wants to merge 1 commit into
releasefrom
dependabot/composer/dompdf/dompdf-3.1.6
Open

Bump dompdf/dompdf from 3.1.0 to 3.1.6#17
dependabot[bot] wants to merge 1 commit into
releasefrom
dependabot/composer/dompdf/dompdf-3.1.6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 26, 2026

Copy link
Copy Markdown

Bumps dompdf/dompdf from 3.1.0 to 3.1.6.

Release notes

Sourced from dompdf/dompdf's releases.

Dompdf 3.1.6

This release addresses the following announced vulnerabilities:

Vulnerability References Type Severity
Chroot Validation Bypass GHSA-wvh6-f5jh-8gw4 Validation Bypass Moderate
File existence oracle via font-face stylesheet declaration GHSA-7x2p-4jvh-6384 Information Disclosure Moderate
Local file read due to improper file path validation in SVG images encoded as data-URI GHSA-cx96-42px-69fm Information Disclosure Moderate
Embedded SVG images can leak existence of files and directories within the filesystem GHSA-j8qw-6jw8-r297 Information Disclosure Moderate
Denial of Service via Resource Exhaustion using Oversized Image Bitmaps GHSA-f5gf-2cj8-52g2 Denial of Service Moderate
Uncontrolled resource consumption based on declared BMP dimensions GHSA-8hg6-c449-896m Denial of Service Moderate

Review the Securing Dompdf wiki document for guidance on steps you can take to mitigate your installation against potential exploit.

Full Changelog: dompdf/dompdf@v3.1.5...v3.1.6

Dompdf 3.1.5

What's Changed

Full Changelog: dompdf/dompdf@v3.1.4...v3.1.5

Dompdf 3.1.4

Change Highlights

Full Changelog: dompdf/dompdf@v3.1.3...v3.1.4

Dompdf 3.1.3

Change Highlights

Full Changelog: dompdf/dompdf@v3.1.2...v3.1.3

Dompdf 3.1.2

Change Highlights

  • Fixes issue with the font selection logic introduced in release 3.1.1 dompdf/dompdf#3661

Issues and PRs can be found in the release milestone. All changes since the previous release can be found in the commit history.

... (truncated)

Commits
  • 6d4b4eb Update VERSION to 3.1.6
  • eb10166 Fix variable reference in background image size calculation
  • 76d832d Improve some error handling
  • b6860e5 Update unit tests
  • 252b6d5 Allow remote resources in style image tests
  • 525684d Skip badly formed data-URI conversion to blob URI
  • b61c570 Add tests for image size limits
  • 7c65e7b Allow limits to images based on byte size
  • 89164ea Return additional image metadata from dompdf_getimagesize
  • bf7b02f Reject SVG whose file references do not resolve
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [dompdf/dompdf](https://github.com/dompdf/dompdf) from 3.1.0 to 3.1.6.
- [Release notes](https://github.com/dompdf/dompdf/releases)
- [Commits](dompdf/dompdf@v3.1.0...v3.1.6)

---
updated-dependencies:
- dependency-name: dompdf/dompdf
  dependency-version: 3.1.6
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file php Pull requests that update php code labels Jul 26, 2026
@private-packagist

Copy link
Copy Markdown

composer.lock

Package changes

Package Operation From To About
thecodingmachine/safe add - v3.4.0 view code - License: MIT License
dompdf/dompdf upgrade v3.1.0 ⚠️ v3.1.6 ✅ diff
dompdf/php-font-lib upgrade 1.0.1 1.0.2 diff
dompdf/php-svg-lib upgrade 1.0.0 1.0.2 diff
masterminds/html5 upgrade 2.10.0 2.10.1 diff
sabberworm/php-css-parser upgrade v8.9.0 v9.4.0 diff

Settings · Docs · Powered by Private Packagist

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file php Pull requests that update php code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants