docling-core has 3 CVEs on record. The median CVSS is 8.1 (high).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.1
- Publish → KEV
- —
- Last 90 days
- 0 prev 2
Products
- docling-core 3
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
docling-core vulnerabilities
CVEs affecting docling-core, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-44023High· 8.6Docling Core: Unsafe remote filename resolution
Docling Core: Unsafe remote filename resolution
▾ Twilightdocling-core · docling-coreEPSS 0.43%via OSV
CVE-2026-44019High· 8.1Docling Core: Insufficient validation of image reference URIs
Docling Core: Insufficient validation of image reference URIs
▾ Twilightdocling-core · docling-coreEPSS 0.42%via OSV
CVE-2026-24009High· 8.1PoCdocling-core vulnerable to Remote Code Execution via unsafe PyYAML usage
docling-core vulnerable to Remote Code Execution via unsafe PyYAML usage
▾ Midnightdocling-core · docling-coreEPSS 1.6%via OSV