docling-core@1.7.2

A python library to define and validate data types in Docling.

  • latest version

    3.0.0

  • latest non vulnerable version

  • first published

    1 years ago

  • latest version published

    1 years ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the docling-core package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Server-side Request Forgery (SSRF)

    docling-core is an A python library to define and validate data types in Docling.

    Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) in the resolve_remote_filename() function, which processes headers from remote requests. An attacker can access sensitive files or internal resources by supplying malicious URLs in the Content-Disposition parameter that are resolved to unintended local paths.

    How to fix Server-side Request Forgery (SSRF)?

    Upgrade docling-core to version 2.74.1 or higher.

    [1.5.0,2.74.1)