docling vulnerabilities
CVEs whose affected-version data names the docling package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
8 CVEsRSS
CVE-2026-47214High· 7.1Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.94.0, the HTML backend has unsafe URI and path handling. This vulnerability is fixed in 2.94.0.
CVE-2026-44020High· 7.5Docling: Unsafe XML Entity Expansion in USPTO Patent Backend
Docling: Unsafe XML Entity Expansion in USPTO Patent Backend
CVE-2026-44018Medium· 5.5Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend
Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend
CVE-2026-44016High· 8.2Docling: Unsafe Playwright-based HTML Rendering
Docling: Unsafe Playwright-based HTML Rendering
CVE-2026-44017High· 7.5Docling: Unsafe Zip Extraction in EasyOCR Model Download
Docling: Unsafe Zip Extraction in EasyOCR Model Download
CVE-2026-44022Medium· 5.5Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands
Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands
CVE-2026-31247High· 7.5Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks
Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks
CVE-2026-31248High· 7.5Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks
Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks