docling-core vulnerabilities
CVEs whose affected-version data names the docling-core package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-44023High· 8.6Docling Core: Unsafe remote filename resolution
Docling Core: Unsafe remote filename resolution
▾ Twilightdocling-core · docling-coreEPSS 0.43%via OSV
CVE-2026-44019High· 8.1Docling Core: Insufficient validation of image reference URIs
Docling Core: Insufficient validation of image reference URIs
▾ Twilightdocling-core · docling-coreEPSS 0.42%via OSV
CVE-2026-24009High· 8.1PoCdocling-core vulnerable to Remote Code Execution via unsafe PyYAML usage
docling-core vulnerable to Remote Code Execution via unsafe PyYAML usage
▾ Midnightdocling-core · docling-coreEPSS 1.6%via OSV