{"api_version":"v1","generated_at":"2026-10-08T12:40:00+00:00","product":{"cve_count":3,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-docling-project-docling-core-905c74db38a7","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"docling-core","next_cursor":null,"observations":[{"affected":">= 1.5.0, < 2.74.1","affected_versions_present":true,"cve_id":"CVE-2026-44023","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44023","fixed":"2.74.1.","last_modified":"2026-07-17T18:06:33.532Z","patch_url":"https://github.com/docling-project/docling-core/security/advisories/GHSA-jmmv-h3mp-59v8","primary_source":"","published":"2026-07-16T21:00:49.617Z"},{"affected":">= 2.5.0, < 2.74.1","affected_versions_present":true,"cve_id":"CVE-2026-44019","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44019","fixed":"2.74.1.","last_modified":"2026-07-17T17:50:50.083Z","patch_url":"https://github.com/docling-project/docling-core/security/advisories/GHSA-j5xp-7m2f-49jv","primary_source":"","published":"2026-07-16T20:50:08.807Z"},{"affected":">= 2.21.0, < 2.48.4","affected_versions_present":true,"cve_id":"CVE-2026-24009","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-24009","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-01-22T15:59:19.883Z","patch_url":"https://github.com/docling-project/docling-core/security/advisories/GHSA-vqxf-v2gg-x3hc","primary_source":"","published":"2026-01-22T15:04:52.745Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"docling-project"}}
