PT-2026-46118 · Docling · Docling

CVE-2026-44016

·

Published

2026-06-03

·

Updated

2026-06-26

CVSS v3.1

8.2

High

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Docling versions 2.82.0 through 2.90.x
Description When the HTML backend is explicitly configured for rendering, the Playwright-based rendering feature allows JavaScript execution and unrestricted network access during the processing of untrusted HTML documents. This can enable an attacker to execute arbitrary JavaScript in the rendering context or perform unauthorized network requests to internal services, potentially resulting in Server-Side Request Forgery (SSRF), data exfiltration, or remote code execution in the rendering environment.
Recommendations Update to version 2.91.0. As a temporary workaround, refrain from using render page=True when processing untrusted HTML documents.

Exploit

Fix

RCE

SSRF

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44016
GHSA-PJ2V-GGQH-CMQ2
PYSEC-2026-2142

Affected Products

Docling