CVE-2021-3902
An improper restriction of external entities (XXE) vulnerability in dompdf/dompdf's SVG parser allows for Server-Side Request Forgery (SSRF) and deserialization attacks. This issue affects all versions prior to 2.0.0. The vulnerability can be exploited even if the isRemoteEnabled option is set to false. It allows attackers to perform SSRF, disclose internal image files, and cause PHAR deserialization attacks.
- Affected products
- Dompdf
- Dompdf Project Dompdf
- < 2.0.0
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 0.9% (57th percentile)
- Weakness
- CWE-611
- NVD status
- Analyzed
- Published
- 2024-11-15
CVE-2021-3902 at NVD
No indexed exploits for CVE-2021-3902 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2021-3902 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.