VulnSea

docling has 8 CVEs on record. Disclosures have slowed: 1 in the last 90 days after 7 in the 90 before. The busiest recent month was June 2026 with 6. The median CVSS is 7.5 (high). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
1 prev 7

Weakness classes

Products

  • docling 8
8
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

docling vulnerabilities

CVEs affecting docling, newest first. Open any entry for full detail, references, and exploit status.

8 CVEsRSS

CVE-2026-47214High· 7.1
2mo ago

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.94.0, the HTML backend has unsafe URI and path handling. This vulnerability is fixed in 2.94.0.

Twilightdocling · doclingEPSS 0.37%via NVD
CVE-2026-44020High· 7.5
3mo ago

Docling: Unsafe XML Entity Expansion in USPTO Patent Backend

Docling: Unsafe XML Entity Expansion in USPTO Patent Backend

Twilightdocling · doclingEPSS 0.60%via OSV
CVE-2026-44018Medium· 5.5
3mo ago

Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend

Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend

Sunlitdocling · doclingEPSS 0.16%via OSV
CVE-2026-44016High· 8.2
3mo ago

Docling: Unsafe Playwright-based HTML Rendering

Docling: Unsafe Playwright-based HTML Rendering

Twilightdocling · doclingEPSS 0.59%via OSV
CVE-2026-44017High· 7.5
3mo ago

Docling: Unsafe Zip Extraction in EasyOCR Model Download

Docling: Unsafe Zip Extraction in EasyOCR Model Download

Twilightdocling · doclingEPSS 0.71%via OSV
CVE-2026-44022Medium· 5.5
3mo ago

Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands

Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands

Sunlitdocling · doclingEPSS 0.21%via OSV
CVE-2026-31247High· 7.5
4mo ago

Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks

Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks

Twilightdocling · doclingEPSS 0.35%via OSV
CVE-2026-31248High· 7.5
4mo ago

Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks

Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks

Twilightdocling · doclingEPSS 0.28%via OSV
docling vulnerabilities (CVEs) · VulnSea