Docling Core
- >= 2.5.0, < 2.74.1
A vulnerability in Docling Core versions 2.5.0 and above, prior to 2.74.1, allows local file access through 'file://' image references and accepts large inline 'data:' content without a size limit. This could lead to reading local files accessible by the process or excessive memory consumption from large inline data. The issue has been resolved in version 2.74.1.
Exploitation of this vulnerability could result in unauthorized access to local files readable by the process or excessive memory use from large inline payloads, potentially leading to a denial-of-service condition.
Users are advised to upgrade to Docling Core version 2.74.1 or later. If an immediate upgrade is not possible, untrusted 'file:' and 'data:' image references should be rejected, only approved local or remote image sources allowed, and input size and memory limits applied to processing workers.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.