© 2025-2026 PySpect
First version without a known vulnerability: 2.132.0
Docling: Configured HTTP headers sent to every remote image host named by a document
Fixed in: 2.132.0
Docling has SSRF guard bypass in remote resource fetching (DNS rebinding / multi-record resolution; no IP validation in HTML render mode)
Fixed in: 2.132.0
Docling has arbitrary file read/write (and command execution when shell-escape is enabled) when rendering untrusted TikZ with the opt-in Tectonic engine
Fixed in: 2.132.0
Docling: Crafted DoclingDocument JSON embeds local image files into converted output
Fixed in: 2.131.0
Docling: Unbounded table rowspan/colspan in HTML, JATS, ODS and BoxNote backends causes CPU/memory exhaustion
Fixed in: 2.131.0
Docling imports plugin entry points before the allow_external_plugins check
Fixed in: 2.131.0
Docling: METS-GBS archive member limit enforced after full member enumeration (memory exhaustion during format detection)
Fixed in: 2.131.0
Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode
Fixed in: 2.118.1
Docling: Arbitrary local file read via draw:image xlink:href in the OpenDocument backend
Fixed in: 2.120.3
Docling: Unsafe URI and Path Handling in HTML Backend
Fixed in: 2.94.0
Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands
Fixed in: 2.91.0
Docling: Unsafe XML Entity Expansion in USPTO Patent Backend
Fixed in: 2.74.0
Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend
Fixed in: 2.91.0
Docling: Unsafe Playwright-based HTML Rendering
Fixed in: 2.91.0
Docling: Unsafe Zip Extraction in EasyOCR Model Download
Fixed in: 2.91.0
Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks
Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks