This release includes 1 security fix for security teams reviewing exposed deployments.
Published 1mo
RAG & Retrieval
✓ No known CVEs patched
This release patches 1 known CVE
Topics
ai
convert
document-parser
document-parsing
documents
docx
+9 more
html
markdown
pdf
pdf-converter
pdf-to-json
pdf-to-text
pptx
tables
xlsx
Affected surfaces
deps
Summary
AI summaryUpdates Fix, Feature, and CVE-2026-54283 across a mixed release.
Full changelog
Feature
- Capture picture description API usage (#3632) (
0d629e4) - NVIDIA nemotron-ocr integration (#3136) (
6e4a59b)
Fix
- service: JSON-encode nested options for multipart file uploads (#3672) (
dcee90c) - rapidocr: Propagate num_threads to OpenVINO backend (#3666) (
733a82e) - asciidoc: Fix empty cell handling (#3664) (
f52db93) - Upgrade starlette to 1.3.1 (CVE-2026-54283) (#3673) (
e4fce9c) - service: Fixes for Docling ConfidenceReport parsing in
ConversionResult(#3662) (898dd73) - asciidoc: Parse table cells with format specifiers (#3647) (
7e0aed9) - Resolving issue 3655 for rich tables in docx (#3657) (
6fe4fc3)
Security Fixes
- CVE-2026-54283 — Upgrade starlette to 1.3.1 fixing the vulnerability
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]