VulnSea

docling vulnerabilities

CVEs whose affected-version data names the docling package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

8 CVEsRSS

CVE-2026-47214High· 7.1
2mo ago

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.94.0, the HTML backend has unsafe URI and path handling. This vulnerability is fixed in 2.94.0.

Twilightdocling · doclingEPSS 0.37%via NVD
CVE-2026-44020High· 7.5
3mo ago

Docling: Unsafe XML Entity Expansion in USPTO Patent Backend

Docling: Unsafe XML Entity Expansion in USPTO Patent Backend

Twilightdocling · doclingEPSS 0.60%via OSV
CVE-2026-44018Medium· 5.5
3mo ago

Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend

Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend

Sunlitdocling · doclingEPSS 0.16%via OSV
CVE-2026-44016High· 8.2
3mo ago

Docling: Unsafe Playwright-based HTML Rendering

Docling: Unsafe Playwright-based HTML Rendering

Twilightdocling · doclingEPSS 0.59%via OSV
CVE-2026-44017High· 7.5
3mo ago

Docling: Unsafe Zip Extraction in EasyOCR Model Download

Docling: Unsafe Zip Extraction in EasyOCR Model Download

Twilightdocling · doclingEPSS 0.71%via OSV
CVE-2026-44022Medium· 5.5
3mo ago

Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands

Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands

Sunlitdocling · doclingEPSS 0.21%via OSV
CVE-2026-31247High· 7.5
4mo ago

Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks

Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks

Twilightdocling · doclingEPSS 0.35%via OSV
CVE-2026-31248High· 7.5
4mo ago

Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks

Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks

Twilightdocling · doclingEPSS 0.28%via OSV
docling vulnerabilities (CVEs) · VulnSea