PT-2026-46127 · Docling · Docling

·

CVE-2026-47214

·

Published

2026-06-03

·

Updated

2026-07-02

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions Docling versions prior to 2.94.0
Description The HTML backend fails to perform sufficient validation during resource handling. This allows local file system access via file:// URIs when enable local fetch is set to True, and enables path traversal outside intended directories through absolute paths or ../ sequences. Additionally, the system does not block internal network resources when enable remote fetch is True, fails to validate HTTP redirects, and lacks resource limits for data: URIs and remote image downloads. These issues can lead to Server-Side Request Forgery (SSRF), where an attacker induces the server to make requests to an internal or unintended resource.
Recommendations Update to version 2.94.0. As a temporary workaround, keep both enable local fetch and enable remote fetch set to False when processing untrusted HTML documents.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47214
GHSA-Q29V-XC37-WH5M
PYSEC-2026-2146

Affected Products

Docling