SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-44023

HIGH · CVSS 8.6 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability affects Docling Core versions 1.5.0 to 2.74.1, allowing for Server-Side Request Forgery (SSRF) attacks due to insufficient restrictions on remote request destinations. This flaw can enable attackers to access local files outside the user-defined cache directory by exploiting untrusted URLs. Organizations using affected versions of Docling should prioritize upgrading to version 2.74.1 to mitigate potential data exposure risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-44023
Severity
HIGH
CVSS
8.6
EPSS
0.29%

Original NVD Description

Docling Core defines core data types and transformations for the document processing application Docling. In versions 1.5.0 and above, prior to 2.74.1, docling-core did not sufficiently restrict remote request destinations and could resolve a server-provided Content-Disposition to a local path in an unsafe manner. In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files outside the user-defined cache directory. This issue has been fixed in version 2.74.1.

Related CVEs

Other vulnerabilities affecting the same vendor(s)