SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-44019

HIGH · CVSS 8.1 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Versions 2.5.0 to 2.74.0 of Docling Core are vulnerable to local file access and excessive memory consumption due to improper handling of file references and inline data. This could lead to unauthorized access to local files or denial of service from large payloads in applications that process untrusted image references. Organizations using affected versions should prioritize updating to version 2.74.1 to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-44019
Severity
HIGH
CVSS
8.1
EPSS
0.24%

Original NVD Description

Docling Core defines core data types and transformations for the document processing application Docling. In versions 2.5.0 and above, prior to 2.74.1, docling-core could allow local file:// image references and accepted inline data: content without a decoded-size limit. In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads. This issue has been fixed in version 2.74.1.