CVE-2026-44017·Python vulnerability
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.91.0, the EasyOCR model download functionality extracted ZIP archives without validating member paths, enabling Zip Slip attacks. If an attacker could compromise the model download source (via supply chain attack, DNS spoofing, or MITM), they could write arbitrary files to any location writable by the process, potentially achieving remote code execution by overwriting Python files or system binaries, persistent backdoors by modifying startup scripts or SSH keys, and data corruption or system compromise. This vulnerability is fixed in 2.91.0.
- Severity
- high
- Software
- Python
- Fixed in
- 2.91.0
- Published
- 2026-06-24
Affected versions
Until: 2.91.0
Fixed in: 2.91.0
How to fix this CVE
Update Docling to version 2.91.0 or later to patch the Zip Slip vulnerability in EasyOCR model downloads. This fix adds proper path validation when extracting ZIP archives, preventing attackers from writing files outside the intended directory. Ensure all systems using Docling for document processing apply this update to eliminate the risk of arbitrary file writes and potential RCE through compromised model sources.
sudo dnf update python3-doclingDefensia detects this vulnerability
How to check if you are affected
- Check installed Docling version with: python3 -c "import docling; print(docling.__version__)"
- Verify if EasyOCR models are being downloaded by checking: find ~/.cache -type d -name 'easyocr' 2>/dev/null || find /var/cache -type d -name 'easyocr' 2>/dev/null
- Search for suspicious file extraction patterns in system logs: grep -r 'ZIP\|zipfile\|extract' /var/log/syslog /var/log/audit/audit.log 2>/dev/null | grep -i docling
- Confirm the patch by running: python3 -c "import docling; print('Patched' if docling.__version__ >= '2.91.0' else 'Vulnerable')"
FAQ
What is CVE-2026-44017?
CVE-2026-44017 is a Zip Slip vulnerability in Docling's EasyOCR model downloader that fails to validate archive member paths during extraction. An attacker controlling the model source (through supply chain compromise, DNS spoofing, or MITM) could write malicious files to arbitrary locations, enabling RCE or system compromise.
Is CVE-2026-44017 being actively exploited?
No, this vulnerability is not currently listed on the CISA KEV catalog and no public exploits are documented. However, it remains a high-severity risk due to its potential for RCE if the threat vector materializes.
What versions of Docling are affected by CVE-2026-44017?
All versions of Docling prior to 2.91.0 are vulnerable. The vulnerability was introduced in earlier versions and completely remediated in version 2.91.0.
How do I check if my server is vulnerable to CVE-2026-44017?
Run: python3 -c "import docling; print(docling.__version__)" and verify the version is 2.91.0 or higher. If the version is lower, your system is vulnerable.
Does Defensia detect CVE-2026-44017?
Yes — Defensia's CVE advisory scanner compares installed Docling versions against the NVD database. If Docling is installed on a monitored server, CVE-2026-44017 will appear in your dashboard with remediation steps.
Related Python CVEs
References
- https://github.com/docling-project/docling/releases/tag/v2.91.0
- https://github.com/docling-project/docling/security/advisories/GHSA-cjqg-rq2h-2fvj
- https://access.redhat.com/security/cve/CVE-2026-44017
- https://bugzilla.redhat.com/show_bug.cgi?id=2492448
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44017.json
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-44017. Free for 1 server.
Get started free