docling-core
Docling core data types and transformations
Activity
- Latest release
- 3d ago
- Total releases
- 179
- Cadence
- ~3 days
- Last 12 months
- 66
Reach
- Stars
- 282
Details
- License
- MIT
- First release
- Jul 12, 2024
| Version | Released | |
|---|---|---|
2.96.0
minor
| ||
2.95.0
minor
| ||
2.94.1
patch
| ||
2.94.0
minor
| ||
2.93.0
minor
| ||
2.92.0
minor
| ||
2.91.0
minor
| ||
2.90.0
minor
| ||
2.89.0
minor
| ||
2.88.0
minor
| ||
2.87.1
patch
| ||
2.87.0
minor
| ||
2.86.0
minor
| ||
2.85.0
minor
| ||
2.84.0
minor
| ||
2.83.1
patch
| ||
2.83.0
minor
| ||
2.82.0
minor
| ||
2.81.0
minor
| ||
2.80.0
minor
| ||
2.79.0
minor
| ||
2.78.1
patch
| ||
2.78.0
minor
| ||
2.77.1
patch
| ||
2.77.0
minor
| ||
2.76.0
minor
| ||
2.75.0
minor
| ||
2.74.1
patch
| ||
2.74.0
minor
2 CVEs
CVE-2026-44023
PYSEC-2026-2457
GHSA-jmmv-h3mp-59v8
Jul 13, 2026
Docling Core: Unsafe remote filename resolution
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
ImpactIn versions In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files outside the user-defined cache directory. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible, avoid passing untrusted URLs into remote fetch functionality. References
Affected versions
1.5.0
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
2.0.0
2.0.1
2.1.0
2.10.0
+ 126 more Show less
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.3.0
2.3.1
2.3.2
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.4.0
2.4.1
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44019
PYSEC-2026-2456
GHSA-j5xp-7m2f-49jv
Jul 13, 2026
Docling Core: Insufficient validation of image reference URIs
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
None
High
ImpactIn versions In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible:
References
Affected versions
2.10.0
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
+ 106 more Show less
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.73.0
minor
2 CVEs
CVE-2026-44023
PYSEC-2026-2457
GHSA-jmmv-h3mp-59v8
Jul 13, 2026
Docling Core: Unsafe remote filename resolution
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
ImpactIn versions In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files outside the user-defined cache directory. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible, avoid passing untrusted URLs into remote fetch functionality. References
Affected versions
1.5.0
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
2.0.0
2.0.1
2.1.0
2.10.0
+ 126 more Show less
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.3.0
2.3.1
2.3.2
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.4.0
2.4.1
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44019
PYSEC-2026-2456
GHSA-j5xp-7m2f-49jv
Jul 13, 2026
Docling Core: Insufficient validation of image reference URIs
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
None
High
ImpactIn versions In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible:
References
Affected versions
2.10.0
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
+ 106 more Show less
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.72.0
minor
2 CVEs
CVE-2026-44023
PYSEC-2026-2457
GHSA-jmmv-h3mp-59v8
Jul 13, 2026
Docling Core: Unsafe remote filename resolution
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
ImpactIn versions In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files outside the user-defined cache directory. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible, avoid passing untrusted URLs into remote fetch functionality. References
Affected versions
1.5.0
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
2.0.0
2.0.1
2.1.0
2.10.0
+ 126 more Show less
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.3.0
2.3.1
2.3.2
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.4.0
2.4.1
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44019
PYSEC-2026-2456
GHSA-j5xp-7m2f-49jv
Jul 13, 2026
Docling Core: Insufficient validation of image reference URIs
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
None
High
ImpactIn versions In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible:
References
Affected versions
2.10.0
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
+ 106 more Show less
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.71.0
minor
2 CVEs
CVE-2026-44023
PYSEC-2026-2457
GHSA-jmmv-h3mp-59v8
Jul 13, 2026
Docling Core: Unsafe remote filename resolution
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
ImpactIn versions In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files outside the user-defined cache directory. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible, avoid passing untrusted URLs into remote fetch functionality. References
Affected versions
1.5.0
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
2.0.0
2.0.1
2.1.0
2.10.0
+ 126 more Show less
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.3.0
2.3.1
2.3.2
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.4.0
2.4.1
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44019
PYSEC-2026-2456
GHSA-j5xp-7m2f-49jv
Jul 13, 2026
Docling Core: Insufficient validation of image reference URIs
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
None
High
ImpactIn versions In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible:
References
Affected versions
2.10.0
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
+ 106 more Show less
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.70.2
patch
2 CVEs
CVE-2026-44023
PYSEC-2026-2457
GHSA-jmmv-h3mp-59v8
Jul 13, 2026
Docling Core: Unsafe remote filename resolution
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
ImpactIn versions In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files outside the user-defined cache directory. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible, avoid passing untrusted URLs into remote fetch functionality. References
Affected versions
1.5.0
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
2.0.0
2.0.1
2.1.0
2.10.0
+ 126 more Show less
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.3.0
2.3.1
2.3.2
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.4.0
2.4.1
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44019
PYSEC-2026-2456
GHSA-j5xp-7m2f-49jv
Jul 13, 2026
Docling Core: Insufficient validation of image reference URIs
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
None
High
ImpactIn versions In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible:
References
Affected versions
2.10.0
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
+ 106 more Show less
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.70.1
patch
2 CVEs
CVE-2026-44023
PYSEC-2026-2457
GHSA-jmmv-h3mp-59v8
Jul 13, 2026
Docling Core: Unsafe remote filename resolution
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
ImpactIn versions In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files outside the user-defined cache directory. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible, avoid passing untrusted URLs into remote fetch functionality. References
Affected versions
1.5.0
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
2.0.0
2.0.1
2.1.0
2.10.0
+ 126 more Show less
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.3.0
2.3.1
2.3.2
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.4.0
2.4.1
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44019
PYSEC-2026-2456
GHSA-j5xp-7m2f-49jv
Jul 13, 2026
Docling Core: Insufficient validation of image reference URIs
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
None
High
ImpactIn versions In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible:
References
Affected versions
2.10.0
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
+ 106 more Show less
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.70.0
minor
2 CVEs
CVE-2026-44023
PYSEC-2026-2457
GHSA-jmmv-h3mp-59v8
Jul 13, 2026
Docling Core: Unsafe remote filename resolution
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
ImpactIn versions In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files outside the user-defined cache directory. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible, avoid passing untrusted URLs into remote fetch functionality. References
Affected versions
1.5.0
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
2.0.0
2.0.1
2.1.0
2.10.0
+ 126 more Show less
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.3.0
2.3.1
2.3.2
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.4.0
2.4.1
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44019
PYSEC-2026-2456
GHSA-j5xp-7m2f-49jv
Jul 13, 2026
Docling Core: Insufficient validation of image reference URIs
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
None
High
ImpactIn versions In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible:
References
Affected versions
2.10.0
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
+ 106 more Show less
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.69.0
minor
2 CVEs
CVE-2026-44023
PYSEC-2026-2457
GHSA-jmmv-h3mp-59v8
Jul 13, 2026
Docling Core: Unsafe remote filename resolution
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
ImpactIn versions In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files outside the user-defined cache directory. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible, avoid passing untrusted URLs into remote fetch functionality. References
Affected versions
1.5.0
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
2.0.0
2.0.1
2.1.0
2.10.0
+ 126 more Show less
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.3.0
2.3.1
2.3.2
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.4.0
2.4.1
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44019
PYSEC-2026-2456
GHSA-j5xp-7m2f-49jv
Jul 13, 2026
Docling Core: Insufficient validation of image reference URIs
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
None
High
ImpactIn versions In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible:
References
Affected versions
2.10.0
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
+ 106 more Show less
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.68.0
minor
2 CVEs
CVE-2026-44023
PYSEC-2026-2457
GHSA-jmmv-h3mp-59v8
Jul 13, 2026
Docling Core: Unsafe remote filename resolution
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
ImpactIn versions In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files outside the user-defined cache directory. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible, avoid passing untrusted URLs into remote fetch functionality. References
Affected versions
1.5.0
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
2.0.0
2.0.1
2.1.0
2.10.0
+ 126 more Show less
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.3.0
2.3.1
2.3.2
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.4.0
2.4.1
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44019
PYSEC-2026-2456
GHSA-j5xp-7m2f-49jv
Jul 13, 2026
Docling Core: Insufficient validation of image reference URIs
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
None
High
ImpactIn versions In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible:
References
Affected versions
2.10.0
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
+ 106 more Show less
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.67.1
patch
2 CVEs
CVE-2026-44023
PYSEC-2026-2457
GHSA-jmmv-h3mp-59v8
Jul 13, 2026
Docling Core: Unsafe remote filename resolution
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
ImpactIn versions In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files outside the user-defined cache directory. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible, avoid passing untrusted URLs into remote fetch functionality. References
Affected versions
1.5.0
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
2.0.0
2.0.1
2.1.0
2.10.0
+ 126 more Show less
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.3.0
2.3.1
2.3.2
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.4.0
2.4.1
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44019
PYSEC-2026-2456
GHSA-j5xp-7m2f-49jv
Jul 13, 2026
Docling Core: Insufficient validation of image reference URIs
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
None
High
ImpactIn versions In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible:
References
Affected versions
2.10.0
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
+ 106 more Show less
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.67.0
minor
2 CVEs
CVE-2026-44023
PYSEC-2026-2457
GHSA-jmmv-h3mp-59v8
Jul 13, 2026
Docling Core: Unsafe remote filename resolution
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
ImpactIn versions In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files outside the user-defined cache directory. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible, avoid passing untrusted URLs into remote fetch functionality. References
Affected versions
1.5.0
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
2.0.0
2.0.1
2.1.0
2.10.0
+ 126 more Show less
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.3.0
2.3.1
2.3.2
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.4.0
2.4.1
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44019
PYSEC-2026-2456
GHSA-j5xp-7m2f-49jv
Jul 13, 2026
Docling Core: Insufficient validation of image reference URIs
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
None
High
ImpactIn versions In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible:
References
Affected versions
2.10.0
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
+ 106 more Show less
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.66.0
minor
2 CVEs
CVE-2026-44023
PYSEC-2026-2457
GHSA-jmmv-h3mp-59v8
Jul 13, 2026
Docling Core: Unsafe remote filename resolution
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
ImpactIn versions In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files outside the user-defined cache directory. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible, avoid passing untrusted URLs into remote fetch functionality. References
Affected versions
1.5.0
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
2.0.0
2.0.1
2.1.0
2.10.0
+ 126 more Show less
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.3.0
2.3.1
2.3.2
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.4.0
2.4.1
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44019
PYSEC-2026-2456
GHSA-j5xp-7m2f-49jv
Jul 13, 2026
Docling Core: Insufficient validation of image reference URIs
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
None
High
ImpactIn versions In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible:
References
Affected versions
2.10.0
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
+ 106 more Show less
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.65.2
patch
2 CVEs
CVE-2026-44023
PYSEC-2026-2457
GHSA-jmmv-h3mp-59v8
Jul 13, 2026
Docling Core: Unsafe remote filename resolution
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
ImpactIn versions In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files outside the user-defined cache directory. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible, avoid passing untrusted URLs into remote fetch functionality. References
Affected versions
1.5.0
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
2.0.0
2.0.1
2.1.0
2.10.0
+ 126 more Show less
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.3.0
2.3.1
2.3.2
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.4.0
2.4.1
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44019
PYSEC-2026-2456
GHSA-j5xp-7m2f-49jv
Jul 13, 2026
Docling Core: Insufficient validation of image reference URIs
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
None
High
ImpactIn versions In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible:
References
Affected versions
2.10.0
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
+ 106 more Show less
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.65.1
patch
2 CVEs
CVE-2026-44023
PYSEC-2026-2457
GHSA-jmmv-h3mp-59v8
Jul 13, 2026
Docling Core: Unsafe remote filename resolution
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
ImpactIn versions In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files outside the user-defined cache directory. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible, avoid passing untrusted URLs into remote fetch functionality. References
Affected versions
1.5.0
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
2.0.0
2.0.1
2.1.0
2.10.0
+ 126 more Show less
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.3.0
2.3.1
2.3.2
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.4.0
2.4.1
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44019
PYSEC-2026-2456
GHSA-j5xp-7m2f-49jv
Jul 13, 2026
Docling Core: Insufficient validation of image reference URIs
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
None
High
ImpactIn versions In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible:
References
Affected versions
2.10.0
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
+ 106 more Show less
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.65.0
minor
2 CVEs
CVE-2026-44023
PYSEC-2026-2457
GHSA-jmmv-h3mp-59v8
Jul 13, 2026
Docling Core: Unsafe remote filename resolution
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
ImpactIn versions In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files outside the user-defined cache directory. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible, avoid passing untrusted URLs into remote fetch functionality. References
Affected versions
1.5.0
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
2.0.0
2.0.1
2.1.0
2.10.0
+ 126 more Show less
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.3.0
2.3.1
2.3.2
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.4.0
2.4.1
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44019
PYSEC-2026-2456
GHSA-j5xp-7m2f-49jv
Jul 13, 2026
Docling Core: Insufficient validation of image reference URIs
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
None
High
ImpactIn versions In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible:
References
Affected versions
2.10.0
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
+ 106 more Show less
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.64.0
minor
2 CVEs
CVE-2026-44023
PYSEC-2026-2457
GHSA-jmmv-h3mp-59v8
Jul 13, 2026
Docling Core: Unsafe remote filename resolution
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
ImpactIn versions In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files outside the user-defined cache directory. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible, avoid passing untrusted URLs into remote fetch functionality. References
Affected versions
1.5.0
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
2.0.0
2.0.1
2.1.0
2.10.0
+ 126 more Show less
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.3.0
2.3.1
2.3.2
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.4.0
2.4.1
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44019
PYSEC-2026-2456
GHSA-j5xp-7m2f-49jv
Jul 13, 2026
Docling Core: Insufficient validation of image reference URIs
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
None
High
ImpactIn versions In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible:
References
Affected versions
2.10.0
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
+ 106 more Show less
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.63.0
minor
2 CVEs
CVE-2026-44023
PYSEC-2026-2457
GHSA-jmmv-h3mp-59v8
Jul 13, 2026
Docling Core: Unsafe remote filename resolution
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
ImpactIn versions In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files outside the user-defined cache directory. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible, avoid passing untrusted URLs into remote fetch functionality. References
Affected versions
1.5.0
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
2.0.0
2.0.1
2.1.0
2.10.0
+ 126 more Show less
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.3.0
2.3.1
2.3.2
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.4.0
2.4.1
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44019
PYSEC-2026-2456
GHSA-j5xp-7m2f-49jv
Jul 13, 2026
Docling Core: Insufficient validation of image reference URIs
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
None
High
ImpactIn versions In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible:
References
Affected versions
2.10.0
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
+ 106 more Show less
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.62.0
minor
2 CVEs
CVE-2026-44023
PYSEC-2026-2457
GHSA-jmmv-h3mp-59v8
Jul 13, 2026
Docling Core: Unsafe remote filename resolution
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
ImpactIn versions In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files outside the user-defined cache directory. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible, avoid passing untrusted URLs into remote fetch functionality. References
Affected versions
1.5.0
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
2.0.0
2.0.1
2.1.0
2.10.0
+ 126 more Show less
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.3.0
2.3.1
2.3.2
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.4.0
2.4.1
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44019
PYSEC-2026-2456
GHSA-j5xp-7m2f-49jv
Jul 13, 2026
Docling Core: Insufficient validation of image reference URIs
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
None
High
ImpactIn versions In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible:
References
Affected versions
2.10.0
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
+ 106 more Show less
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.61.0
minor
2 CVEs
CVE-2026-44023
PYSEC-2026-2457
GHSA-jmmv-h3mp-59v8
Jul 13, 2026
Docling Core: Unsafe remote filename resolution
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
ImpactIn versions In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files outside the user-defined cache directory. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible, avoid passing untrusted URLs into remote fetch functionality. References
Affected versions
1.5.0
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
2.0.0
2.0.1
2.1.0
2.10.0
+ 126 more Show less
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.3.0
2.3.1
2.3.2
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.4.0
2.4.1
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44019
PYSEC-2026-2456
GHSA-j5xp-7m2f-49jv
Jul 13, 2026
Docling Core: Insufficient validation of image reference URIs
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
None
High
ImpactIn versions In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible:
References
Affected versions
2.10.0
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
+ 106 more Show less
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.60.2
patch
2 CVEs
CVE-2026-44023
PYSEC-2026-2457
GHSA-jmmv-h3mp-59v8
Jul 13, 2026
Docling Core: Unsafe remote filename resolution
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
ImpactIn versions In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files outside the user-defined cache directory. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible, avoid passing untrusted URLs into remote fetch functionality. References
Affected versions
1.5.0
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
2.0.0
2.0.1
2.1.0
2.10.0
+ 126 more Show less
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.3.0
2.3.1
2.3.2
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.4.0
2.4.1
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44019
PYSEC-2026-2456
GHSA-j5xp-7m2f-49jv
Jul 13, 2026
Docling Core: Insufficient validation of image reference URIs
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
None
High
ImpactIn versions In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible:
References
Affected versions
2.10.0
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
+ 106 more Show less
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.60.1
patch
2 CVEs
CVE-2026-44023
PYSEC-2026-2457
GHSA-jmmv-h3mp-59v8
Jul 13, 2026
Docling Core: Unsafe remote filename resolution
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
ImpactIn versions In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files outside the user-defined cache directory. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible, avoid passing untrusted URLs into remote fetch functionality. References
Affected versions
1.5.0
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
2.0.0
2.0.1
2.1.0
2.10.0
+ 126 more Show less
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.3.0
2.3.1
2.3.2
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.4.0
2.4.1
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44019
PYSEC-2026-2456
GHSA-j5xp-7m2f-49jv
Jul 13, 2026
Docling Core: Insufficient validation of image reference URIs
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
None
High
ImpactIn versions In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible:
References
Affected versions
2.10.0
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
+ 106 more Show less
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.60.0
minor
2 CVEs
CVE-2026-44023
PYSEC-2026-2457
GHSA-jmmv-h3mp-59v8
Jul 13, 2026
Docling Core: Unsafe remote filename resolution
8.6
/ 10
High
Network
Low
None
None
Unchanged
High
Low
Low
ImpactIn versions In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files outside the user-defined cache directory. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible, avoid passing untrusted URLs into remote fetch functionality. References
Affected versions
1.5.0
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
2.0.0
2.0.1
2.1.0
2.10.0
+ 126 more Show less
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.3.0
2.3.1
2.3.2
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.4.0
2.4.1
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44019
PYSEC-2026-2456
GHSA-j5xp-7m2f-49jv
Jul 13, 2026
Docling Core: Insufficient validation of image reference URIs
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
None
High
ImpactIn versions In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads. PatchesPatched in Users should upgrade to:
WorkaroundsIf upgrading is not immediately possible:
References
Affected versions
2.10.0
2.11.0
2.12.0
2.12.1
2.13.0
2.13.1
2.14.0
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
+ 106 more Show less
2.17.1
2.17.2
2.18.0
2.18.1
2.19.0
2.19.1
2.20.0
2.21.0
2.21.1
2.21.2
2.22.0
2.23.0
2.23.1
2.23.2
2.23.3
2.24.0
2.24.1
2.25.0
2.26.0
2.26.1
2.26.2
2.26.3
2.26.4
2.27.0
2.28.0
2.28.1
2.29.0
2.30.0
2.30.1
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.33.1
2.34.0
2.34.1
2.34.2
2.35.0
2.36.0
2.37.0
2.38.0
2.38.1
2.38.2
2.39.0
2.40.0
2.41.0
2.42.0
2.43.0
2.43.1
2.44.0
2.44.1
2.44.2
2.45.0
2.46.0
2.47.0
2.48.0
2.48.1
2.48.2
2.48.3
2.48.4
2.49.0
2.5.0
2.5.1
2.50.0
2.50.1
2.51.0
2.51.1
2.52.0
2.53.0
2.54.0
2.54.1
2.55.0
2.56.0
2.57.0
2.58.0
2.58.1
2.59.0
2.6.0
2.6.1
2.60.0
2.60.1
2.60.2
2.61.0
2.62.0
2.63.0
2.64.0
2.65.0
2.65.1
2.65.2
2.66.0
2.67.0
2.67.1
2.68.0
2.69.0
2.7.0
2.7.1
2.70.0
2.70.1
2.70.2
2.71.0
2.72.0
2.73.0
2.74.0
2.8.0
2.9.0
Fixed in
2.74.1
References
Updated Jul 13, 2026 · Source: OSV.dev |