Docling Core Unsafe Remote Filename Resolution Vulnerability Allowing SSRF

Vulnerability

A vulnerability in Docling Core versions 1.5.0 and above, prior to 2.74.1, allowed for unsafe resolution of server-provided Content-Disposition headers to local paths. This issue could be exploited in applications that accept untrusted URLs, leading to Server-Side Request Forgery (SSRF) attacks that target local files outside the user-defined cache directory.

Impact

Exploitation of this vulnerability could result in unauthorized access to local files, potentially leading to the disclosure of sensitive information.

Remediation

Users are advised to upgrade to Docling Core version 2.74.1 or later. If an immediate upgrade is not possible, avoid using untrusted URLs with the remote fetch functionality.

Added: Jul 16, 2026, 11:14 PM
Updated: Jul 16, 2026, 11:14 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.0
exploitability
6.8
remediation
0.0
relevance
9.6
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.