Vulnerabilidades en docling-project
10 resultadosAnálisis Vexday
O docling-project apresenta 10 vulnerabilidades registradas, com 9 delas publicadas nos últimos 90 dias, indicando um projeto em fase de descoberta de falhas. Nenhuma está sob exploração ativa no momento, mas a ausência de críticas (CVSS 9+) não diminui a relevância da fraqueza dominante CWE-22 (Path Traversal), que pode permitir acesso não autorizado a arquivos. O volume recente de divulgações sugere necessidade de monitoramento contínuo enquanto vulnerabilidades são identificadas e remediadas.
CVE-2026-24009HIGHDocling Core vulnerable to Remote Code Execution via unsafe PyYAML usageEPSS 1.4%CVE-2026-44017HIGHDocling: Unsafe Zip Extraction in EasyOCR Model DownloadEPSS 0.5%CVE-2026-44016HIGHDocling: Unsafe Playwright-based HTML RenderingEPSS 0.4%CVE-2026-44020HIGHDocling: Unsafe XML Entity Expansion in USPTO Patent BackendEPSS 0.3%CVE-2026-44023HIGHDocling Core has unsafe remote filename resolutionEPSS 0.3%CVE-2026-44019HIGHDocling Core has insufficient validation of image reference URIsEPSS 0.2%CVE-2026-47214HIGHDocling: Unsafe URI and Path Handling in HTML BackendEPSS 0.2%CVE-2026-44520MEDIUMDocling-Graph: SSRF via Missing Internal IP Validation in URLInputHandlerEPSS 0.2%CVE-2026-44022MEDIUMDocling: Potential Path Traversal via LaTeX \includegraphics and \input CommandsEPSS 0.2%CVE-2026-44018MEDIUMDocling: Unsafe Archive Extraction and XML Parsing in METS-GBS BackendEPSS 0.1%