Local File Access Vulnerability in Docling Core Document Processing Application
CVE-2026-44019
8.1HIGH
What is CVE-2026-44019?
The Docling Core application, utilized for document processing, is vulnerable to local file inclusion due to the handling of image references and inline data content without appropriate size limits. In versions ranging from 2.5.0 to just before 2.74.1, this vulnerability could permit unauthorized access to local files that the application can read or lead to excessive memory usage from improperly sized inline payloads. This flaw poses significant risks in environments where untrusted image references are processed, making it essential for users to upgrade to version 2.74.1 or newer to ensure security.
Affected Version(s)
docling-core >= 2.5.0, < 2.74.1
