In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade docling to version 2.74.0 or higher.
docling is a SDK and CLI for parsing PDF, DOCX, HTML, and more, to a unified document representation for powering downstream workflows such as gen AI applications.
Affected versions of this package are vulnerable to XML Entity Expansion in backend/xml/uspto_backend.py's use of parseString(). An attacker can cause resource exhaustion or read local filtes by submitting malicious USPTO patent XML files.