SCA: security update for docling (GHSA-m88r-rg27-5xfg)

critical Tenable Cloud Security Plugin ID 442610

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Docling simplifies document processing by parsing diverse formats and providing integrations with the
generative AI ecosystem. From 2.13.0 until 2.74.0, the USPTO patent XML parser used the standard
xml.sax.parseString() without protection against XML External Entity (XXE) attacks. An attacker could
craft malicious USPTO patent XML files with external entity references that could read arbitrary files
from the server filesystem, perform Server-Side Request Forgery (SSRF) attacks, or cause denial of service
through entity expansion (Billion Laughs attack). The vulnerability affects three USPTO patent format
parsers: ICE (v4.x), Grant v2.5, and Application v1.x. This vulnerability is fixed in 2.74.0.
(CVE-2026-44020)

Solution

Update the docling library and its related packages to version 2.74.0 or later.

See Also

https://github.com/advisories/GHSA-m88r-rg27-5xfg

Plugin Details

Severity: Critical

ID: 442610

Version: Revision 1.4

Type: Local

Family: SCA Checks

Published: 6/4/2026

Updated: 6/30/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.75

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-44020

CVSS v3

Risk Factor: Critical

Base Score: 9.4

Temporal Score: 8.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 6/3/2026

Vulnerability Publication Date: 6/3/2026

Reference Information

CVE: CVE-2026-44020

cwe: CWE-776