CyberRota Analysis
AI-GeneratedVersions 2.5.0 to 2.74.0 of Docling Core are vulnerable to local file access and excessive memory consumption due to improper handling of file references and inline data. This could lead to unauthorized access to local files or denial of service from large payloads in applications that process untrusted image references. Organizations using affected versions should prioritize updating to version 2.74.1 to mitigate these risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Docling Core defines core data types and transformations for the document processing application Docling. In versions 2.5.0 and above, prior to 2.74.1, docling-core could allow local file:// image references and accepted inline data: content without a decoded-size limit. In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads. This issue has been fixed in version 2.74.1.