VYPR
High severity8.1NVD Advisory· Published Jul 16, 2026· Updated Jul 17, 2026

CVE-2026-44019

CVE-2026-44019

Description

Docling Core defines core data types and transformations for the document processing application Docling. In versions 2.5.0 and above, prior to 2.74.1, docling-core could allow local file:// image references and accepted inline data: content without a decoded-size limit. In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads. This issue has been fixed in version 2.74.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
docling-corePyPI
>= 2.5.0, < 2.74.12.74.1

Affected products

2

Patches

Vulnerability mechanics

References

3

News mentions

1