PT-2026-45850 · Unknown · Docling-Core

CVE-2026-44019

·

Published

2026-06-02

·

Updated

2026-07-16

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions docling-core versions 2.5.0 through 2.74.0
Description Insufficient input sanitization when processing specific documents allows for path traversal, enabling remote attackers to read arbitrary files from the host server. The software allows local file:// image references and accepts inline data: content without a decoded-size limit. In applications that accept untrusted image references, this can lead to the disclosure of local files readable by the process or excessive memory consumption due to large inline payloads.
Recommendations Upgrade to version 2.74.1 or later. As a temporary workaround, reject file: and data: image references from untrusted input. Allow only approved local or remote image sources. Apply input size and memory limits to processing workers.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44019
GHSA-J5XP-7M2F-49JV
PYSEC-2026-2456

Affected Products

Docling-Core