CVE-2026-44023: Docling Docling-Core

High severity, CVSS 8.6. EPSS: 0.4% chance of exploitation in the next 30 days.

Docling Core defines core data types and transformations for the document processing application Docling. In versions 1.5.0 and above, prior to 2.74.1, docling-core did not sufficiently restrict remote request destinations and could resolve a server-provided Content-Disposition to a local path in an unsafe manner. In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files outside the user-defined cache directory. This issue has been fixed in version 2.74.1.

Affected products

  • Docling Docling-Core: from 1.5.0, before 2.74.1 (fixed in 2.74.1)

Published 2026-07-16. Last modified 2026-07-30.