docling records
8 published records for vendor docling.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-409 Improper Handling of Highly Compressed Data (Data Amplification)1
- CWE-502 Deserialization of Untrusted Data1
- CWE-73 External Control of File Name or Path1
- CWE-776 Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2026-24009Proof of concept | Docling Core vulnerable to Remote Code Execution via unsafe PyYAML usagedocling · docling-core · CWE-502 | Critical9.8 | — | 1.6% | Jan 22, 2026 |
34Monitor | CVE-2026-44023No exploit | Docling Core has unsafe remote filename resolutiondocling · docling-core · CWE-22 | High8.6 | — | 0.4% | Jul 16, 2026 |
32Monitor | CVE-2026-44016No exploit | Docling: Unsafe Playwright-based HTML Renderingdocling · docling · CWE-94 | High8.2 | — | 0.6% | Jun 24, 2026 |
30Monitor | CVE-2026-44017No exploit | Docling: Unsafe Zip Extraction in EasyOCR Model Downloaddocling · docling · CWE-22 | High7.5 | — | 0.7% | Jun 24, 2026 |
30Monitor | CVE-2026-44020No exploit | Docling: Unsafe XML Entity Expansion in USPTO Patent Backenddocling · docling · CWE-776 | High7.5 | — | 0.6% | Jun 24, 2026 |
28Monitor | CVE-2026-47214No exploit | Docling: Unsafe URI and Path Handling in HTML Backenddocling · docling · CWE-73 | High7.1 | — | 0.4% | Jun 26, 2026 |
28Monitor | CVE-2026-44018No exploit | Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backenddocling · docling · CWE-409 | High7.1 | — | 0.2% | Jun 26, 2026 |
22Monitor | CVE-2026-44022No exploit | Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commandsdocling · docling · CWE-22 | Medium5.5 | — | 0.2% | Jun 24, 2026 |
- CVE-2026-2400939Monitor
Docling Core vulnerable to Remote Code Execution via unsafe PyYAML usage
CriticalCVSS 9.8Proof of conceptEPSS 2%docling · docling-coreJan 22, 2026
- CVE-2026-4402334Monitor
Docling Core has unsafe remote filename resolution
HighCVSS 8.6No exploitEPSS 0%docling · docling-coreJul 16, 2026
- CVE-2026-4401632Monitor
Docling: Unsafe Playwright-based HTML Rendering
HighCVSS 8.2No exploitEPSS 1%docling · doclingJun 24, 2026
- CVE-2026-4401730Monitor
Docling: Unsafe Zip Extraction in EasyOCR Model Download
HighCVSS 7.5No exploitEPSS 1%docling · doclingJun 24, 2026
- CVE-2026-4402030Monitor
Docling: Unsafe XML Entity Expansion in USPTO Patent Backend
HighCVSS 7.5No exploitEPSS 1%docling · doclingJun 24, 2026
- CVE-2026-4721428Monitor
Docling: Unsafe URI and Path Handling in HTML Backend
HighCVSS 7.1No exploitEPSS 0%docling · doclingJun 26, 2026
- CVE-2026-4401828Monitor
Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend
HighCVSS 7.1No exploitEPSS 0%docling · doclingJun 26, 2026
- CVE-2026-4402222Monitor
Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands
MediumCVSS 5.5No exploitEPSS 0%docling · doclingJun 24, 2026