PYSEC-2026-2457
Docling Core: Unsafe remote filename resolution
Quick fix
PYSEC-2026-2457 — docling-core: upgrade to the fixed version with the command below.
pip install --upgrade 'docling-core>=2.74.1'Details
### Impact In versions `>= 1.5.0, < 2.74.1`, `docling-core` did not sufficiently restrict remote request destinations and could resolve a server-provided `Content-Disposition` to a local path in an unsafe manner.
In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files outside the user-defined cache directory.
### Patches Patched in `docling-core` `2.74.1`. The fix adds stricter validation for remote destinations and normalizes server-provided filenames before use.
Users should upgrade to: - `docling-core` `>= 2.74.1`
### Workarounds If upgrading is not immediately possible, avoid passing untrusted URLs into remote fetch functionality.
### References - Fix release: [`v2.74.1`](https://github.com/docling-project/docling-core/releases/tag/v2.74.1)
Are you affected?
Enter the version of the package you're using.
Affected packages
1.5.0Fixed in: 2.74.1pip install --upgrade 'docling-core>=2.74.1'References
- https://github.com/docling-project/docling-core/security/advisories/GHSA-jmmv-h3mp-59v8[WEB]
- https://github.com/docling-project/docling-core[PACKAGE]
- https://github.com/docling-project/docling-core/releases/tag/v2.74.1[WEB]
- https://pypi.org/project/docling-core[PACKAGE]
- https://github.com/advisories/GHSA-jmmv-h3mp-59v8[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-44023[ADVISORY]