CVE-2026-44023
published 2026-07-16CVE-2026-44023: Docling Core defines core data types and transformations for the document processing application Docling. In versions 1.5.0 and above, prior to 2.74.1…
PriorityP352high8.6CVSS 3.1
AVNACLPRNUINSUCHILAL
EPSS
0.43%
36.6th percentile
Docling Core defines core data types and transformations for the document processing application Docling. In versions 1.5.0 and above, prior to 2.74.1, docling-core did not sufficiently restrict remote request destinations and could resolve a server-provided Content-Disposition to a local path in an unsafe manner. In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files outside the user-defined cache directory. This issue has been fixed in version 2.74.1.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| docling-project | docling-core | — | — |
| docling-project | docling-core | >= 1.5.0 < 2.74.1 | 2.74.1 |
| docling | docling-core | >= 1.5.0 < 2.74.1 | 2.74.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
docling-project docling-core up to 2.74.0 Data Types/Transformations server-side request forgery
vuldb·2026-07-16·CVSS 8.6
CVE-2026-44023 [HIGH] docling-project docling-core up to 2.74.0 Data Types/Transformations server-side request forgery
A vulnerability was found in docling-project docling-core up to 2.74.0 and classified as problematic. This affects an unknown part of the component Data Types/Transformations. The manipulation results in server-side request forgery.
This vulnerability is identified as CVE-2026-44023. The attack can be executed remotely. There is not any exploit available.
GHSA
Docling Core: Unsafe remote filename resolution
ghsa·2026-06-03
CVE-2026-44023 [HIGH] CWE-22 Docling Core: Unsafe remote filename resolution
Docling Core: Unsafe remote filename resolution
### Impact
In versions `>= 1.5.0, = 2.74.1`
### Workarounds
If upgrading is not immediately possible, avoid passing untrusted URLs into remote fetch functionality.
### References
- Fix release: [`v2.74.1`](https://github.com/docling-project/docling-core/releases/tag/v2.74.1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-16
Published