CVE-2022-41343: Dompdf Project Dompdf
High severity, CVSS 7.5. EPSS: 6% chance of exploitation in the next 30 days.
registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not halt font registration, as demonstrated by a @font-face rule.
Affected products
- Dompdf Project Dompdf: before 2.0.1 (fixed in 2.0.1)
Published 2022-09-25. Last modified 2026-06-17.