High severity8.1NVD Advisory· Published Jul 16, 2026· Updated Jul 17, 2026
CVE-2026-44019
CVE-2026-44019
Description
Docling Core defines core data types and transformations for the document processing application Docling. In versions 2.5.0 and above, prior to 2.74.1, docling-core could allow local file:// image references and accepted inline data: content without a decoded-size limit. In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads. This issue has been fixed in version 2.74.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
docling-corePyPI | >= 2.5.0, < 2.74.1 | 2.74.1 |
Affected products
2- Range: >= 2.5.0, < 2.74.1
Patches
Vulnerability mechanics
References
3News mentions
1- Docling Project: Eight High-Severity Vulnerabilities Disclosed TogetherVypr Intelligence · Jun 3, 2026