{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44016.json"
      }
    ],
    "title": "docling: Docling: Remote code execution via malicious HTML in Playwright-based rendering",
    "tracking": {
      "current_release_date": "2026-06-30T03:59:11+00:00",
      "generator": {
        "date": "2026-06-30T03:59:11+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.0"
        }
      },
      "id": "CVE-2026-44016",
      "initial_release_date": "2026-06-24T17:42:42.434000+00:00",
      "revision_history": [
        {
          "date": "2026-06-24T17:42:42.434000+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-06-25T19:15:11.528371+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-06-30T03:59:11+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat OpenShift AI (RHOAI)",
                "product": {
                  "name": "Red Hat OpenShift AI (RHOAI)",
                  "product_id": "red_hat_openshift_ai_(rhoai)",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openshift_ai"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat OpenShift AI (RHOAI)"
          },
          {
            "category": "product_version",
            "name": "rhoai/odh-autorag-rhel9",
            "product": {
              "name": "rhoai/odh-autorag-rhel9",
              "product_id": "rhoai/odh-autorag-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/odh-autorag-rhel9?repository_url=registry.redhat.io/rhoai/odh-autorag-rhel9"
              }
            }
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhoai/odh-autorag-rhel9 as a component of Red Hat OpenShift AI (RHOAI)",
          "product_id": "red_hat_openshift_ai_(rhoai):rhoai/odh-autorag-rhel9"
        },
        "product_reference": "rhoai/odh-autorag-rhel9",
        "relates_to_product_reference": "red_hat_openshift_ai_(rhoai)"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-44016",
      "cwe": {
        "id": "CWE-918",
        "name": "Server-Side Request Forgery (SSRF)"
      },
      "discovery_date": "2026-06-24T18:06:17.549498+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "red_hat_openshift_ai_(rhoai):rhoai/odh-autorag-rhel9"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2492339"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Docling. If the HTML backend is explicitly configured for rendering, a remote attacker could exploit a vulnerability in the Playwright-based rendering feature by crafting malicious HTML documents. This could allow the attacker to execute arbitrary JavaScript or make unauthorized network requests, potentially leading to Server-Side Request Forgery (SSRF) attacks, data exfiltration, or remote code execution.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "docling: Docling: Remote code execution via malicious HTML in Playwright-based rendering",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This vulnerability is rated as Important. While Docling's HTML backend rendering feature is deactivated by default in Red Hat OpenShift AI, an explicitly configured instance processing untrusted HTML documents could allow a remote attacker to execute arbitrary JavaScript or make unauthorized network requests. This could lead to Server-Side Request Forgery (SSRF), data exfiltration, or remote code execution within the rendering environment. However, Red Hat OpenShift AI (RHOAI) is not affected as the vulnerable code is not present.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "red_hat_openshift_ai_(rhoai):rhoai/odh-autorag-rhel9"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-44016"
        },
        {
          "category": "external",
          "summary": "RHBZ#2492339",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492339"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-44016",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-44016"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-44016",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44016"
        },
        {
          "category": "external",
          "summary": "https://github.com/docling-project/docling/releases/tag/v2.91.0",
          "url": "https://github.com/docling-project/docling/releases/tag/v2.91.0"
        },
        {
          "category": "external",
          "summary": "https://github.com/docling-project/docling/security/advisories/GHSA-pj2v-ggqh-cmq2",
          "url": "https://github.com/docling-project/docling/security/advisories/GHSA-pj2v-ggqh-cmq2"
        }
      ],
      "release_date": "2026-06-24T17:42:42.434000+00:00",
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L",
            "version": "3.1"
          },
          "products": [
            "red_hat_openshift_ai_(rhoai):rhoai/odh-autorag-rhel9"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "red_hat_openshift_ai_(rhoai):rhoai/odh-autorag-rhel9"
          ]
        }
      ],
      "title": "docling: Docling: Remote code execution via malicious HTML in Playwright-based rendering"
    }
  ]
}