A vulnerability classified as problematic was found in Dompdf up to 3.15. Affected by this issue is some unknown functionality of the component CSS @font-face directive. Such manipulation of the argument _dompdf_show_warnings leads to information disclosure.

This vulnerability is listed as CVE-2026-55555. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is advised.