StackRadar

CVE-2026-59942

Medium

Advisory

Published 22 Jul 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.007
53rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
25
of 17,781 indexed, latest versions
Container images
21
deployed by those charts
Fix available
1 of 1
affected package

Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps

Carried by container images the latest versions of 25 of 17,781 indexed charts deploy, on 21 images.

Affected packageAffected versionsFixed inImages
dompdf/dompdfcomposerv0.8.6, v1.0.2, v1.1.1, v1.2.1+7 more3.1.621
OSV records
GHSA-f5gf-2cj8-52g2

Charts affected

25 by stars
ChartLatestAffected imagesRadar Score
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2026-59942.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
dompdf/dompdf@v2.0.0
3.1.6

Open the chart page →

18,509
bookstackgabe565Verified publisher0.20.01 of 1See more

bookstack gabe565 0.20.0

1 of the 1 container images this version deploys carry CVE-2026-59942.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/bookstack:version-v24.12.1cc795b254b73
dompdf/dompdf@v3.0.2
3.1.6

Open the chart page →

2,811
bookstackbookstack-mgVerified publisher0.3.11 of 2See more

bookstack bookstack-mg 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-59942.

Container imageDigestPackageFixed in
linuxserver/bookstack:26.05.202605282ebf97852661
dompdf/dompdf@v3.1.5
3.1.6

Open the chart page →

1,896
commonground-gatewaycommonground-gateway1.5.41 of 7See more

commonground-gateway commonground-gateway 1.5.4

1 of the 7 container images this version deploys carry CVE-2026-59942.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
dompdf/dompdf@v2.0.1
3.1.6

Open the chart page →

9,724
akauntingf3k-techVerified publisher1.3121.01 of 4See more

akaunting f3k-tech 1.3121.0

1 of the 4 container images this version deploys carry CVE-2026-59942.

Container imageDigestPackageFixed in
akaunting/akaunting:3.1.21-fpm-alpine-nginxe7d5c245b1a0
dompdf/dompdf@v2.0.8
3.1.6

Open the chart page →

4,333
monicageek-cookbookVerified publisher8.2.01 of 1See more

monica geek-cookbook 8.2.0

1 of the 1 container images this version deploys carry CVE-2026-59942.

Container imageDigestPackageFixed in
library/monica:3.7.0-apacheceb1ba4196ab
dompdf/dompdf@v1.1.1
3.1.6

Open the chart page →

2,096
opencatalogiopencatalogi1.0.61 of 8See more

opencatalogi opencatalogi 1.0.6

1 of the 8 container images this version deploys carry CVE-2026-59942.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
dompdf/dompdf@v2.0.1
3.1.6

Open the chart page →

14,838
waardepapierenwaardepapieren1.0.01 of 3See more

waardepapieren waardepapieren 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-59942.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-php:latestb2666ffcbad8
dompdf/dompdf@v0.8.6
3.1.6

Open the chart page →

8,079
waardepapieren-baliewaardepapieren-balie1.0.01 of 3See more

waardepapieren-balie waardepapieren-balie 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-59942.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-balie-php:latestf36c423cd259
dompdf/dompdf@v0.8.6
3.1.6

Open the chart page →

7,871
commonground-gatewaycommonground-gateway-frontend0.1.51 of 4See more

commonground-gateway commonground-gateway-frontend 0.1.5

1 of the 4 container images this version deploys carry CVE-2026-59942.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
dompdf/dompdf@v2.0.1
3.1.6

Open the chart page →

2,825
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-59942.

Container imageDigestPackageFixed in
conduction/conduction-ui-php:dev2744565516e8
dompdf/dompdf@v0.8.6
3.1.6

Open the chart page →

12,907
espocrmespocrmVerified publisher1.0.11 of 2See more

espocrm espocrm 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-59942.

Container imageDigestPackageFixed in
espocrm/espocrm:9.3.101b5a24504ed9
dompdf/dompdf@v3.1.4
3.1.6

Open the chart page →

6,431
monicagabe565Verified publisher0.10.01 of 2See more

monica gabe565 0.10.0

1 of the 2 container images this version deploys carry CVE-2026-59942.

Container imageDigestPackageFixed in
library/monica:4.1.2-fpm-alpine6d1b2bd0947e
dompdf/dompdf@v2.0.8
3.1.6

Open the chart page →

1,173
bookstackgeek-cookbookVerified publisher5.2.01 of 1See more

bookstack geek-cookbook 5.2.0

1 of the 1 container images this version deploys carry CVE-2026-59942.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/bookstack:version-v21.12f05447347ff1
dompdf/dompdf@v1.1.1
3.1.6

Open the chart page →

1,269
icinga2geek-cookbookVerified publisher4.2.01 of 1See more

icinga2 geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-59942.

Container imageDigestPackageFixed in
jordan/icinga2:latestf75025fe8ea8
dompdf/dompdf@v3.1.5
3.1.6

Open the chart page →

9,077
openemrgeek-cookbookVerified publisher5.2.01 of 1See more

openemr geek-cookbook 5.2.0

1 of the 1 container images this version deploys carry CVE-2026-59942.

Container imageDigestPackageFixed in
openemr/openemr:6.1.089eaa6d9a4e3
dompdf/dompdf@v1.1.1
3.1.6

Open the chart page →

8,392
akauntingnas-helm-chartsVerified publisher1.0.31 of 2See more

akaunting nas-helm-charts 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-59942.

Container imageDigestPackageFixed in
akaunting/akaunting:3.0.1552811b36ec3a
dompdf/dompdf@v2.0.3
3.1.6

Open the chart page →

12,813
commonground-gatewayopencatalogi1.5.31 of 7See more

commonground-gateway opencatalogi 1.5.3

1 of the 7 container images this version deploys carry CVE-2026-59942.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
dompdf/dompdf@v2.0.1
3.1.6

Open the chart page →

9,724
panproto-application-nldesign0.1.01 of 5See more

pan proto-application-nldesign 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-59942.

Container imageDigestPackageFixed in
conduction/pan-php:dev24f03c57568f
dompdf/dompdf@v0.8.6
3.1.6

Open the chart page →

8,725
shopwarerobjuz2.0.01 of 6See more

shopware robjuz 2.0.0

1 of the 6 container images this version deploys carry CVE-2026-59942.

Container imageDigestPackageFixed in
shyim/shopware:6.4.6.0a951c0e6b836
dompdf/dompdf@v1.0.2
3.1.6

Open the chart page →

2,972
bookstackschmitzis0.1.11 of 1See more

bookstack schmitzis 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59942.

Container imageDigestPackageFixed in
solidnerd/bookstack:21.12762ffd5c51d3
dompdf/dompdf@v1.1.1
3.1.6

Open the chart page →

2,751
snipeitschmitzis6.1.01 of 2See more

snipeit schmitzis 6.1.0

1 of the 2 container images this version deploys carry CVE-2026-59942.

Container imageDigestPackageFixed in
snipe/snipe-it:v8.3.1141ebf2386fe
dompdf/dompdf@v2.0.8
3.1.6

Open the chart page →

6,094
commonground-gatewayskeleton-pip0.1.71 of 5See more

commonground-gateway skeleton-pip 0.1.7

1 of the 5 container images this version deploys carry CVE-2026-59942.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
dompdf/dompdf@v2.0.1
3.1.6

Open the chart page →

2,825
icingawebsvtech-public-helm-charts1.0.01 of 2See more

icingaweb svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-59942.

Container imageDigestPackageFixed in
svtechnmaa/svtech_icingaweb2:v1.0.2a59d0b81dde2
dompdf/dompdf@v2.0.3
3.1.6

Open the chart page →

2,038
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-59942.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
dompdf/dompdf@v1.2.1
3.1.6

Open the chart page →

7,552

Container images carrying it

21 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
dompdf/dompdf@v2.0.1
3.1.6
5
akaunting/akaunting:3.0.1552811b36ec3a
dompdf/dompdf@v2.0.3
3.1.6
1
akaunting/akaunting:3.1.21-fpm-alpine-nginxe7d5c245b1a0
dompdf/dompdf@v2.0.8
3.1.6
1
conduction/conduction-ui-php:dev2744565516e8
dompdf/dompdf@v0.8.6
3.1.6
1
conduction/pan-php:dev24f03c57568f
dompdf/dompdf@v0.8.6
3.1.6
1
espocrm/espocrm:9.3.101b5a24504ed9
dompdf/dompdf@v3.1.4
3.1.6
1
jordan/icinga2:latestf75025fe8ea8
dompdf/dompdf@v3.1.5
3.1.6
1
library/monica:4.1.2-fpm-alpine6d1b2bd0947e
dompdf/dompdf@v2.0.8
3.1.6
1
library/monica:3.7.0-apacheceb1ba4196ab
dompdf/dompdf@v1.1.1
3.1.6
1
linuxserver/bookstack:26.05.202605282ebf97852661
dompdf/dompdf@v3.1.5
3.1.6
1
openemr/openemr:6.1.089eaa6d9a4e3
dompdf/dompdf@v1.1.1
3.1.6
1
shyim/shopware:6.4.6.0a951c0e6b836
dompdf/dompdf@v1.0.2
3.1.6
1
snipe/snipe-it:v8.3.1141ebf2386fe
dompdf/dompdf@v2.0.8
3.1.6
1
snipe/snipe-it:v6.0.1455fb7636a98c
dompdf/dompdf@v2.0.0
3.1.6
1
solidnerd/bookstack:21.12762ffd5c51d3
dompdf/dompdf@v1.1.1
3.1.6
1
svtechnmaa/svtech_icingaweb2:v1.0.2a59d0b81dde2
dompdf/dompdf@v2.0.3
3.1.6
1
ghcr.io/conductionnl/waardepapieren-balie-php:latestf36c423cd259
dompdf/dompdf@v0.8.6
3.1.6
1
ghcr.io/conductionnl/waardepapieren-php:latestb2666ffcbad8
dompdf/dompdf@v0.8.6
3.1.6
1
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
dompdf/dompdf@v1.2.1
3.1.6
1
ghcr.io/linuxserver/bookstack:version-v24.12.1cc795b254b73
dompdf/dompdf@v3.0.2
3.1.6
1
ghcr.io/linuxserver/bookstack:version-v21.12f05447347ff1
dompdf/dompdf@v1.1.1
3.1.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.