8.1
CVE-2026-44019
- EPSS 0.24%
- Veröffentlicht 16.07.2026 20:50:08
- Zuletzt bearbeitet 17.07.2026 18:36:41
- CVE-Watchlists
- Unerledigt
Docling Core has insufficient validation of image reference URIs
Docling Core defines core data types and transformations for the document processing application Docling. In versions 2.5.0 and above, prior to 2.74.1, docling-core could allow local file:// image references and accepted inline data: content without a decoded-size limit. In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads. This issue has been fixed in version 2.74.1.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerdocling-project
≫
Produkt
docling-core
Version
>= 2.5.0, < 2.74.1
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.144 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 8.1 | 2.8 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
CWE-73 External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.
https://github.com/docling-project/docling-core/security/advisories/GHSA-j5xp-7m2f-49jv
https://github.com/docling-project/docling-core/releases/tag/v2.74.1