CVE-2026-44019High· 8.1▾ TwilightDocling Core: Insufficient validation of image reference URIs
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 17.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.2%
0.2% → 0.4%
In versions >= 2.5.0, < 2.74.1, docling-core could allow local file:// image references and accepted inline data: content without a decoded-size limit.
In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads.
Patched in docling-core 2.74.1.
The fix blocks local file URIs by default and adds a size limit for decoded inline image data.
Users should upgrade to:
docling-core >= 2.74.1If upgrading is not immediately possible:
file: and data: image references from untrusted inputv2.74.1docling-core >= 2.5.0, < 2.74.1Upgrade to a patched release:
docling-core 2.74.1Connected by shared product, vendor, weakness, or advisory.