CVE-2026-24009General(docling / docling-core)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Docling Core (or docling-core) is a library that defines core data types and transformations in the document processing application Docling. A PyYAML-related Remote Code Execution (RCE) vulnerability, namely CVE-2020-14343, is exposed in docling-core starting in version 2.21.0 and prior to version 2.48.4, specifically only if the application uses pyyaml prior to version 5.4 and invokes `docling_core.types.doc.DoclingDocument.load_from_yaml()` passing it untrusted YAML data. The vulnerability has been patched in docling-core version 2.48.4. The fix mitigates the issue by switching `PyYAML` deserialization from `yaml.FullLoader` to `yaml.SafeLoader`, ensuring that untrusted data cannot trigger code execution. Users who cannot immediately upgrade docling-core can alternatively ensure that the installed version of PyYAML is 5.4 or greater.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • docling-core

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • General: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
docling-core

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-19: 203-19
Signal classification1 categories
General
2100.0%
Referenced assets1 URL
Full discourse2 posts
  • Avi@avi_lum
    General

    @JustineTunney @oliviscusAI This looks much better to be honest. Is there supply chain risk in your project? This is genuinely interesting (https://www.oligo.security/blog/docling-rce-a-shadow-vulnerability-introduced-via-pyyaml-cve-2026-24009)

    Post summary

    The comment merely references a blog post about CVE‑2026‑24009 with no additional information on proof of concept, exploitation, or mitigation.

    10000161
    298 followersView on X
  • Avi@avi_lum
    General

    @oliviscusAI These AI "magic" context creators have many security pitfalls. I think it's only a matter of time something like this will happen again but in this project: https://www.oligo.security/blog/docling-rce-a-shadow-vulnerability-introduced-via-pyyaml-cve-2026-24009

    Post summary

    The tweet merely links to a blog post about CVE‑2026‑24009, providing no additional details on exploits, patches, or active usage.

    00010135
    298 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdoclingdocling-core-python-

Explore more