Junglewise Threat Intelligence

CVE-2026-44023: Docling Core SSRF and path traversal in remote filename resolution

CVE-2026-44023 · Severity: high · CVSS 8.6 · Published 2026-07-16

Technologies: docling-core (PyPI). Vendors: PyPI.

Executive brief

Docling Core, a library used for document processing and data transformation, contains a security flaw in how it handles remote file requests. An attacker could provide a malicious web link that tricks the system into accessing or overwriting sensitive local files on the server instead of the intended document. This could lead to the exposure of private data or disruption of the document processing service.

Technical details

Docling Core versions 1.5.0 through 2.74.0 are vulnerable to a combination of Server-Side Request Forgery (SSRF) and Path Traversal (CWE-22). The library fails to sufficiently restrict remote request destinations and unsafely resolves server-provided 'Content-Disposition' headers to local file paths. An attacker can exploit this by providing a crafted URL that, when processed, allows the resolution of filenames outside the intended user-defined cache directory. This can result in unauthorized reading of local files (Confidentiality: High) and limited modification or service impact (Integrity/Availability: Low). The issue is fixed in version 2.74.1, which implements stricter validation and filename normalization.

Affected products

  • docling-project docling-core >= 1.5.0, < 2.74.1

Timeline

  • 2026-04-22: patched: Version 2.74.1 released
  • 2026-06-02: advisory: GitHub Security Advisory published
  • 2026-07-16: disclosed: CVE published to NVD

References

Related threats