Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-2457
  • PyPI/docling-core
Docling Core: Unsafe remote filename resolution 13 Jul
  • Fix available
  • Severity - 8.6 (High)
PYSEC-2026-2456
  • PyPI/docling-core
Docling Core: Insufficient validation of image reference URIs 13 Jul
  • Fix available
  • Severity - 8.1 (High)
PYSEC-2026-2454
  • PyPI/docling
Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks 13 Jul
  • No fix available
  • Severity - 7.5 (High)
PYSEC-2026-2455
  • PyPI/docling
Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks 13 Jul
  • No fix available
  • Severity - 7.5 (High)
PYSEC-2026-2458
  • PyPI/docling-graph
docling-graph has SSRF via Missing Internal IP Validation in URLInputHandler 13 Jul
  • Fix available
  • Severity - 5.7 (Medium)
PYSEC-2026-1313
  • PyPI/docling-core
docling-core vulnerable to Remote Code Execution via unsafe PyYAML usage 07 Jul
  • Fix available
  • Severity - 8.1 (High)
PYSEC-2026-2146
  • PyPI/docling
See record for full details 26 Jun
  • Fix available
  • Severity - 7.1 (High)
PYSEC-2026-2144
  • PyPI/docling
See record for full details 26 Jun
  • Fix available
  • Severity - 7.1 (High)
PYSEC-2026-2145
  • PyPI/docling
See record for full details 24 Jun
  • Fix available
  • Severity - 5.5 (Medium)
PYSEC-2026-240
  • PyPI/docling
See record for full details 24 Jun
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-2143
  • PyPI/docling
See record for full details 24 Jun
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-2142
  • PyPI/docling
See record for full details 24 Jun
  • Fix available
  • Severity - 8.2 (High)
GHSA-jmmv-h3mp-59v8
  • PyPI/docling-core
Docling Core: Unsafe remote filename resolution 03 Jun
  • Fix available
  • Severity - 8.6 (High)
GHSA-j5xp-7m2f-49jv
  • PyPI/docling-core
Docling Core: Insufficient validation of image reference URIs 03 Jun
  • Fix available
  • Severity - 8.1 (High)
GHSA-q29v-xc37-wh5m
  • PyPI/docling
Docling: Unsafe URI and Path Handling in HTML Backend 03 Jun
  • Fix available
  • Severity - 7.1 (High)
GHSA-2j5p-7p5m-cvqr
  • PyPI/docling
Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands 03 Jun
  • Fix available
  • Severity - 5.5 (Medium)