CVE-2026-59941 is an uncontrolled resource consumption vulnerability in Dompdf when processing BMP images. The flaw arises because the library trusts BMP header-declared image dimensions and allocates image resources during GD-based conversion without adequately bounding width × height or overall pixel count before allocation. A crafted BMP can therefore declare extremely large dimensions while remaining small on disk, causing disproportionate memory allocation and CPU usage during rendering. The issue can be reached through attacker-supplied BMP content, including BMP data embedded in attacker-controlled HTML as a data URI.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small proof-of-concept for CVE-2026-59942, a Dompdf <= 3.1.5 denial-of-service vulnerability caused by resource exhaustion during rendering of a crafted HTML document. The repo contains three functional files: exploit.py generates the malicious payload, render.php acts as a minimal vulnerable Dompdf entry point, and monitor.py observes PHP process CPU/RAM usage during exploitation. exploit.py uses Pillow and os.urandom() to create a 30000x30000 high-entropy grayscale image, encodes it as base64 PNG, and embeds it into an HTML img data URI saved as payload.html. The intended effect is to force Dompdf to fully decompress and process a huge bitmap in memory when render() is called. render.php loads HTML from php://stdin, initializes Dompdf with HTML5 parsing and remote access enabled, and invokes render(); this is the actual trigger point for the DoS. monitor.py is auxiliary only and uses psutil to watch php processes and report memory and CPU consumption until the target crashes. There is no shellcode, persistence, lateral movement, or code execution capability; the exploit strictly provides denial of service by causing excessive memory allocation and CPU saturation in the PDF rendering path. The repository is a genuine PoC exploit rather than a scanner or detector.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.