Vulnerabilities

Last updated 3 hours ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
docling Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode Medium Risk 5.9 8 hours ago 8 hours ago
docling-slim Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode Medium Risk 5.9 8 hours ago 8 hours ago
docling Docling: Arbitrary local file read via draw:image xlink:href in the OpenDocument backend Medium Risk 6.0 10 hours ago 10 hours ago
docling Docling: Unsafe Zip Extraction in EasyOCR Model Download High Risk 7.5 4 months ago 1 month ago
docling Docling: Unsafe XML Entity Expansion in USPTO Patent Backend High Risk 7.5 4 months ago 1 month ago
org.apache.camel:camel-docling Apache Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in DoclingProducer Critical 9.1 3 months ago 1 month ago
docling Docling: Unsafe URI and Path Handling in HTML Backend High Risk 7.1 4 months ago 2 months ago
docling Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend Medium Risk 5.5 4 months ago 2 months ago
docling Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands Medium Risk 5.5 4 months ago 2 months ago
docling Docling: Unsafe Playwright-based HTML Rendering High Risk 8.2 4 months ago 2 months ago
docling-core Docling Core: Insufficient validation of image reference URIs High Risk 8.1 4 months ago 2 months ago
docling-core Docling Core: Unsafe remote filename resolution High Risk 8.6 4 months ago 2 months ago
docling Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks High Risk 7.5 4 months ago 2 months ago
docling-graph docling-graph has SSRF via Missing Internal IP Validation in URLInputHandler Medium Risk 5.7 5 months ago 2 months ago
docling Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks High Risk 7.5 4 months ago 2 months ago
docling Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks High Risk 7.5 2 months ago 2 months ago
docling Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks High Risk 7.5 2 months ago 2 months ago
docling-core Docling Core: Unsafe remote filename resolution High Risk 8.6 2 months ago 2 months ago
docling-graph docling-graph has SSRF via Missing Internal IP Validation in URLInputHandler Medium Risk 5.7 2 months ago 2 months ago
docling-core Docling Core: Insufficient validation of image reference URIs High Risk 8.1 2 months ago 2 months ago
docling No summary available High Risk 8.2 3 months ago 2 months ago
docling No summary available High Risk 7.5 3 months ago 2 months ago
docling No summary available High Risk 7.1 3 months ago 2 months ago
docling No summary available Medium Risk 5.5 3 months ago 2 months ago
docling No summary available High Risk 7.1 3 months ago 2 months ago
docling-core docling-core vulnerable to Remote Code Execution via unsafe PyYAML usage High Risk 8.1 8 months ago 3 months ago
docling-core docling-core vulnerable to Remote Code Execution via unsafe PyYAML usage High Risk 8.1 3 months ago 3 months ago
docling No summary available High Risk 7.5 3 months ago 3 months ago