Junglewise Threat Intelligence

CVE-2026-44520: Docling-Graph SSRF in URLInputHandler

CVE-2026-44520 · Severity: medium · CVSS 5.7 · Published 2026-05-14

Vendors: PyPI.

Executive brief

docling-graph is a tool used to transform unstructured documents into knowledge graphs. A security vulnerability in how it handles web addresses allows an attacker to force the application to make requests to internal servers or cloud metadata services. This could lead to the theft of sensitive credentials or unauthorized access to internal company data.

Technical details

The URLInputHandler class in docling_graph/core/input/handlers.py fails to validate whether user-supplied URLs resolve to private, loopback, or link-local IP addresses. The URLValidator only checks for a valid scheme and non-empty netloc, and the use of requests.head() with allow_redirects=True allows attackers to bypass simple checks via redirects. An attacker controlling the --source CLI argument or PipelineConfig.source API parameter can reach internal services or cloud metadata endpoints (e.g., 169.254.169.254) to extract IAM credentials. The vulnerability is fixed in version 1.5.1 by implementing strict IP validation and disabling automatic redirect following.

Affected products

  • docling-project docling-graph <= 1.5.0

Timeline

  • 2026-05-01: disclosed
  • 2026-05-07: advisory: GitHub Advisory published
  • 2026-05-14: other: NVD published

References