Vulnerability Description
Docling Core defines core data types and transformations for the document processing application Docling. In versions 1.5.0 and above, prior to 2.74.1, docling-core did not sufficiently restrict remote request destinations and could resolve a server-provided Content-Disposition to a local path in an unsafe manner. In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files outside the user-defined cache directory. This issue has been fixed in version 2.74.1.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Docling | Docling-Core | >= 1.5.0, < 2.74.1 |
Related Weaknesses (CWE)
References
- https://github.com/docling-project/docling-core/releases/tag/v2.74.1ProductRelease Notes
- https://github.com/docling-project/docling-core/security/advisories/GHSA-jmmv-h3PatchVendor Advisory
FAQ
What is CVE-2026-44023?
CVE-2026-44023 is a vulnerability with a CVSS score of 8.6 (HIGH). Docling Core defines core data types and transformations for the document processing application Docling. In versions 1.5.0 and above, prior to 2.74.1, docling-core did not sufficiently restrict remot...
How severe is CVE-2026-44023?
CVE-2026-44023 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-44023?
Check the references section above for vendor advisories and patch information. Affected products include: Docling Docling-Core.