PT-2026-45850 · Unknown · Docling-Core
CVE-2026-44019
·
Published
2026-06-02
·
Updated
2026-07-16
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
docling-core versions 2.5.0 through 2.74.0
Description
Insufficient input sanitization when processing specific documents allows for path traversal, enabling remote attackers to read arbitrary files from the host server. The software allows local
file:// image references and accepts inline data: content without a decoded-size limit. In applications that accept untrusted image references, this can lead to the disclosure of local files readable by the process or excessive memory consumption due to large inline payloads.Recommendations
Upgrade to version 2.74.1 or later.
As a temporary workaround, reject
file: and data: image references from untrusted input.
Allow only approved local or remote image sources.
Apply input size and memory limits to processing workers.Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Docling-Core