CVE-2026-44023High· 8.6▾ TwilightDocling Core: Unsafe remote filename resolution
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 17.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
0.3% → 0.4%
In versions >= 1.5.0, < 2.74.1, docling-core did not sufficiently restrict remote request destinations and could resolve a server-provided Content-Disposition to a local path in an unsafe manner.
In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files outside the user-defined cache directory.
Patched in docling-core 2.74.1.
The fix adds stricter validation for remote destinations and normalizes server-provided filenames before use.
Users should upgrade to:
docling-core >= 2.74.1If upgrading is not immediately possible, avoid passing untrusted URLs into remote fetch functionality.
v2.74.1docling-core >= 1.5.0, < 2.74.1Upgrade to a patched release:
docling-core 2.74.1Connected by shared product, vendor, weakness, or advisory.