Docling Docling-Core vulnerabilities
2 known vulnerabilities affecting docling/docling-core.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1
Vulnerabilities
Page 1 of 1
CVE-2026-24009P2CRITICALCVSS 9.8≥ 2.21.0, < 2.48.42026-01-22
CVE-2026-24009 [CRITICAL] CVE-2026-24009: Docling Core (or docling-core) is a library that defines core data types and transformations in the
Docling Core (or docling-core) is a library that defines core data types and transformations in the document processing application Docling. A PyYAML-related Remote Code Execution (RCE) vulnerability, namely CVE-2020-14343, is exposed in docling-core starting in version 2.21.0 and prior to version 2.48.4, specifically only if the application uses pyyaml pr
nvd
CVE-2026-44023P3HIGHCVSS 8.6≥ 1.5.0, < 2.74.12026-07-16
CVE-2026-44023 [HIGH] CWE-22 CVE-2026-44023: Docling Core defines core data types and transformations for the document processing application Doc
Docling Core defines core data types and transformations for the document processing application Docling. In versions 1.5.0 and above, prior to 2.74.1, docling-core did not sufficiently restrict remote request destinations and could resolve a server-provided Content-Disposition to a local path in an unsafe manner. In applications that accept untrusted
nvd