Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

docling-project — Vulnerabilities & Security Advisories 20

Browse all 20 CVE security advisories affecting docling-project. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates vulnerabilities associated with the vendor docling-project, covering products, weaknesses, and tags within the software supply chain. It collects known security flaws, including configuration errors and code defects, spanning the full historical record of reported issues. Readers can use this aggregation to track the vendor's advisory history, analyze specific weakness classes, and review the vulnerability lifecycle of related products. The data provides a consolidated view for security teams to assess risk exposure without navigating individual CVE entries.

Top products by docling-project: docling docling-core docling-graph
CVE ID Title CVSS Severity Published
CVE-2026-105751 Docling: Arbitrary local file read via draw:image xlink:href in the OpenDocument backend — docling CWE-22 6.9 Medium 2026-10-05
CVE-2026-105750 Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode — docling CWE-552 5.9 Medium 2026-10-05
CVE-2026-105749 Docling: Unbounded table rowspan/colspan in HTML, JATS, ODS and BoxNote backends causes CPU/memory exhaustion — docling CWE-400 6.5 Medium 2026-10-05
CVE-2026-105748 Docling: Crafted DoclingDocument JSON embeds local image files into converted output — docling CWE-73 4.3 Medium 2026-10-05
CVE-2026-105747 Docling: METS-GBS archive member limit enforced after full member enumeration (memory exhaustion during format detection) — docling CWE-409 4.3 Medium 2026-10-05
CVE-2026-105746 Docling: KServe v2 OCR engine does not enforce enable_remote_services — docling CWE-668 2.2 Low 2026-10-05
CVE-2026-105745 Docling: Plugin entry points are imported before the allow_external_plugins check — docling CWE-696 6.7 Medium 2026-10-05
CVE-2026-105744 Docling: Arbitrary file read/write (and command execution when shell-escape is enabled) when rendering untrusted TikZ with the opt-in Tectonic engine — docling CWE-22 7.5 High 2026-10-05
CVE-2026-105743 Docling: SSRF guard bypass in remote resource fetching (DNS rebinding / multi-record resolution; no IP validation in HTML render mode) — docling CWE-367 4.0 Medium 2026-10-05
CVE-2026-105742 Docling: Configured HTTP headers sent to every remote image host named by a document — docling CWE-201 3.7 Low 2026-10-05
CVE-2026-44023 Docling Core has unsafe remote filename resolution — docling-core CWE-22 8.6 High 2026-07-16
CVE-2026-44019 Docling Core has insufficient validation of image reference URIs — docling-core CWE-73 8.1 High 2026-07-16
CVE-2026-47214 Docling: Unsafe URI and Path Handling in HTML Backend — docling CWE-73 7.1 High 2026-06-26
CVE-2026-44018 Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend — docling CWE-409 5.5 Medium 2026-06-26
CVE-2026-44017 Docling: Unsafe Zip Extraction in EasyOCR Model Download — docling CWE-22 7.5 High 2026-06-24
CVE-2026-44022 Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands — docling CWE-22 5.5 Medium 2026-06-24
CVE-2026-44020 Docling: Unsafe XML Entity Expansion in USPTO Patent Backend — docling CWE-776 7.5 High 2026-06-24
CVE-2026-44016 Docling: Unsafe Playwright-based HTML Rendering — docling CWE-94 8.2 High 2026-06-24
CVE-2026-44520 Docling-Graph: SSRF via Missing Internal IP Validation in URLInputHandler — docling-graph CWE-601 5.7 Medium 2026-05-14
CVE-2026-24009 Docling Core vulnerable to Remote Code Execution via unsafe PyYAML usage — docling-core CWE-502 8.1 High 2026-01-22

This page lists every published CVE security advisory associated with docling-project. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.