PT-2026-46121 · Docling · Docling

CVE-2026-44020

·

Published

2026-06-03

·

Updated

2026-06-26

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
Name of the Vulnerable Software and Affected Versions Docling versions prior to 2.74.0
Description The USPTO patent XML parser uses the xml.sax.parseString() function without protection against XML External Entity (XXE) attacks. This allows an attacker to use malicious XML files with external entity references to read arbitrary files from the server filesystem, perform Server-Side Request Forgery (SSRF), or cause a denial of service via entity expansion, also known as a Billion Laughs attack.
Recommendations Update to version 2.74.0. Avoid processing USPTO patent XML files from untrusted sources. Implement resource limits for memory and CPU time when processing patent documents.

Exploit

Fix

DoS

XML Entity Expansion

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44020
GHSA-M88R-RG27-5XFG
PYSEC-2026-240

Affected Products

Docling