CVE 7.1 HIGH

Docling: Unsafe URI and Path Handling in HTML Backend_CVE-2026-47214

7.1 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L

Description

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.94.0, the HTML backend has unsafe URI and path handling. This vulnerability is fixed in 2.94.0.

Basic Information

ID CVE-2026-47214
Source GitHub_M
Published Jun 26, 2026 at 15:45

Affected Product

Vendor docling-project
Product docling
Version < 2.94.0
Affected Versions docling-project docling < 2.94.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.