PYSEC-2026-2456
Docling Core: Insufficient validation of image reference URIs
Quick fix
PYSEC-2026-2456 — docling-core: upgrade to the fixed version with the command below.
pip install --upgrade 'docling-core>=2.74.1'Details
### Impact In versions `>= 2.5.0, < 2.74.1`, `docling-core` could allow local `file://` image references and accepted inline `data:` content without a decoded-size limit.
In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads.
### Patches Patched in `docling-core` `2.74.1`. The fix blocks local file URIs by default and adds a size limit for decoded inline image data.
Users should upgrade to: - `docling-core` `>= 2.74.1`
### Workarounds If upgrading is not immediately possible: - reject `file:` and `data:` image references from untrusted input - allow only approved local or remote image sources - apply input size and memory limits to processing workers
### References - Fix release: [`v2.74.1`](https://github.com/docling-project/docling-core/releases/tag/v2.74.1)
Are you affected?
Enter the version of the package you're using.
Affected packages
2.5.0Fixed in: 2.74.1pip install --upgrade 'docling-core>=2.74.1'References
- https://github.com/docling-project/docling-core/security/advisories/GHSA-j5xp-7m2f-49jv[WEB]
- https://github.com/docling-project/docling-core[PACKAGE]
- https://github.com/docling-project/docling-core/releases/tag/v2.74.1[WEB]
- https://pypi.org/project/docling-core[PACKAGE]
- https://github.com/advisories/GHSA-j5xp-7m2f-49jv[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-44019[ADVISORY]