PyPI package
docling
pkg:pypi/docling
Vulnerabilities (5)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-47214 | Hig | 7.1 | < 2.94.0 | 2.94.0 | Jun 26, 2026 | Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.94.0, the HTML backend has unsafe URI and path handling. This vulnerability is fixed in 2.94.0. | |
| CVE-2026-44018 | Med | 5.5 | >= 2.45.0, < 2.91.0 | 2.91.0 | Jun 26, 2026 | Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend's XML parsing and the input document format detection lacked security controls. An attacker could craft ma | |
| CVE-2026-44022 | Med | 5.5 | >= 2.73.0, < 2.91.0 | 2.91.0 | Jun 24, 2026 | Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.73.0 until 2.91.0, he LaTeX backend's handling of \includegraphics, \input, and \include commands lacked path containment validation. Attackers co | |
| CVE-2026-44020 | Hig | 7.5 | >= 2.13.0, < 2.74.0 | 2.74.0 | Jun 24, 2026 | Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.13.0 until 2.74.0, the USPTO patent XML parser used the standard xml.sax.parseString() without protection against XML External Entity (XXE) attack | |
| CVE-2026-44016 | Hig | 8.2 | >= 2.82.0, < 2.91.0 | 2.91.0 | Jun 24, 2026 | Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. FIn versions >= 2.82.0, < 2.91.0, if the HTML backend was explicitly configured for rendering (rendering option by default deactivated), then the Playwri |
- affected < 2.94.0fixed 2.94.0
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.94.0, the HTML backend has unsafe URI and path handling. This vulnerability is fixed in 2.94.0.
- affected >= 2.45.0, < 2.91.0fixed 2.91.0
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend's XML parsing and the input document format detection lacked security controls. An attacker could craft ma
- affected >= 2.73.0, < 2.91.0fixed 2.91.0
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.73.0 until 2.91.0, he LaTeX backend's handling of \includegraphics, \input, and \include commands lacked path containment validation. Attackers co
- affected >= 2.13.0, < 2.74.0fixed 2.74.0
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.13.0 until 2.74.0, the USPTO patent XML parser used the standard xml.sax.parseString() without protection against XML External Entity (XXE) attack
- affected >= 2.82.0, < 2.91.0fixed 2.91.0
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. FIn versions >= 2.82.0, < 2.91.0, if the HTML backend was explicitly configured for rendering (rendering option by default deactivated), then the Playwri