CVE-2026-44016

HIGH

CVSS v3.1: 8.2 · EPSS: 0.0031 (22.6 percentile)

NetworkNo privilegesCode InjectionSSRFVendor advisory ref

Source data as of:

At a glance

Severity
HIGH
CVSS
8.2 v3.1 · NVD
EPSS
0.0031 (22.6 percentile) · FIRST.org
CISA KEV
No
Type
Code Injection, SSRF · NVD CWE
Attack conditions (CVSS vector)
NetworkNo privileges · Source: NVD Vector
Published
2026-06-24 · Modified: 2026-06-25

CVSS / EPSS / KEV

CVSS v3.1 8.2 / 10 HIGH Source: NVD
EPSS 0.0031 22.6 percentile Source: FIRST.org
CISA KEV No Source: CISA

Source — CVSS: NVD · EPSS: FIRST.org · KEV: CISA. Data & Sources

Description

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. FIn versions >= 2.82.0, < 2.91.0, if the HTML backend was explicitly configured for rendering (rendering option by default deactivated), then the Playwright-based rendering feature could allow JavaScript execution and unrestricted network access when processing untrusted HTML documents. An attacker could craft malicious HTML that executes arbitrary JavaScript in the rendering context or makes unauthorized network requests to internal services, potentially leading to SSRF attacks, data exfiltration, or remote code execution in the rendering environment. This vulnerability is fixed in 2.91.0.

Record details

CVE ID
CVE-2026-44016
CVSS (v3.1)
8.2 (HIGH)
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L
Exploitability subscore
1.6
Impact subscore
6.0
EPSS
0.0031 (22.6 percentile) — 2026-06-26
CISA KEV
No
Weakness (CWE)
CWE-94, CWE-918
Affected configurations (CPE)
0
Published
2026-06-24
Modified
2026-06-25
Status
Undergoing Analysis

References

Reference URLs as listed by NVD, grouped by a mechanical match on the link's host/pattern. Labels describe the link type only.