CVE-2026-44019

Source
https://cve.org/CVERecord?id=CVE-2026-44019
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44019.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-44019
Aliases
Published
2026-07-16T20:50:08.807Z
Modified
2026-08-07T11:49:54.165217176Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H CVSS Calculator
Summary
Docling Core has insufficient validation of image reference URIs
Details

Docling Core defines core data types and transformations for the document processing application Docling. In versions 2.5.0 and above, prior to 2.74.1, docling-core could allow local file:// image references and accepted inline data: content without a decoded-size limit. In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads. This issue has been fixed in version 2.74.1.

Database specific
{
    "cwe_ids": [
        "CWE-400",
        "CWE-73"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44019.json"
}
References

Affected packages

Git / github.com/docling-project/docling-core

Affected ranges

Type
GIT
Repo
https://github.com/docling-project/docling-core
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "2.5.0"
        },
        {
            "fixed": "2.74.1"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v2.*
v2.10.0
v2.11.0
v2.12.0
v2.12.1
v2.13.0
v2.13.1
v2.14.0
v2.15.0
v2.15.1
v2.16.0
v2.16.1
v2.17.0
v2.17.1
v2.17.2
v2.18.0
v2.18.1
v2.19.0
v2.19.1
v2.20.0
v2.21.0
v2.21.1
v2.21.2
v2.22.0
v2.23.0
v2.23.1
v2.23.2
v2.23.3
v2.24.0
v2.24.1
v2.25.0
v2.26.0
v2.26.1
v2.26.2
v2.26.3
v2.26.4
v2.27.0
v2.28.0
v2.28.1
v2.29.0
v2.30.0
v2.30.1
v2.31.0
v2.31.1
v2.31.2
v2.32.0
v2.33.0
v2.33.1
v2.34.0
v2.34.1
v2.34.2
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.38.2
v2.39.0
v2.40.0
v2.41.0
v2.42.0
v2.43.0
v2.43.1
v2.44.0
v2.44.1
v2.44.2
v2.45.0
v2.46.0
v2.47.0
v2.48.0
v2.48.1
v2.48.2
v2.48.3
v2.48.4
v2.49.0
v2.5.0
v2.5.1
v2.50.0
v2.50.1
v2.51.0
v2.51.1
v2.52.0
v2.53.0
v2.54.0
v2.54.1
v2.55.0
v2.56.0
v2.57.0
v2.58.0
v2.58.1
v2.59.0
v2.6.0
v2.6.1
v2.60.0
v2.60.1
v2.60.2
v2.61.0
v2.62.0
v2.63.0
v2.64.0
v2.65.0
v2.65.1
v2.65.2
v2.66.0
v2.67.0
v2.67.1
v2.68.0
v2.69.0
v2.7.0
v2.7.1
v2.70.0
v2.70.1
v2.70.2
v2.71.0
v2.72.0
v2.73.0
v2.74.0
v2.8.0
v2.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44019.json"