Docling is a document-processing and conversion tool whose vulnerability footprint centers on its core product and the attack surface presented by parsing and deserializing untrusted document input. The recurring weakness class of untrusted deserialization reflects the inherent risk of transforming external document formats into structured data without sufficient validation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Docling over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-24009CRITICAL Docling Core (or docling-core) is a library that defines core data types and transformations in the document processing application Docling. A PyYAML-related Remote Code Execution | Jan 22, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-44020CRITICAL Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.13.0 until 2.74.0, the USPTO patent XML parser | Jun 24, 2026 | 9.4 | 35 | NO | NO |
CVE-2026-44016HIGH Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. FIn versions >= 2.82.0, < 2.91.0, if the HTML backend | Jun 24, 2026 | 8.2 | 35 | NO | NO |
CVE-2026-44017HIGH Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.91.0, the EasyOCR model download functiona | Jun 24, 2026 | 8.3 | 32 | NO | NO |
CVE-2026-47214HIGH Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.94.0, the HTML backend has unsafe URI and | Jun 26, 2026 | 7.1 | 29 | NO | NO |
CVE-2026-44018HIGH Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend's XML | Jun 26, 2026 | 7.1 | 29 | NO | NO |
CVE-2026-44022MEDIUM Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.73.0 until 2.91.0, he LaTeX backend's handling | Jun 24, 2026 | 5.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Docling.
Media articles that mention a CVE ID that affects a product developed by Docling — matched by CVE ID, not by vendor name.