CVE-2026-105742
Received Received - Intake

Information Disclosure in Docling via Unrestricted Header Forwarding

Vulnerability report for CVE-2026-105742, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.95.0 until 2.132.0, the HTML image resource loader in docling/backend/utils/image_resource_loader.py forwards headers configured through the HTMLBackendOptions.headers setting to every remote image URL named by an untrusted document when enable_remote_fetch=True and fetch_images=True. The loader does not restrict those credentials to the source document's origin, allowing requests that carry custom headers such as API keys and cookies to follow cross-origin redirects and expose the caller's configured credentials to a document author. The default configuration is not affected because remote fetching and configured headers are required. This issue is fixed in 2.132.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
docling-project docling >= 2.95.0, < 2.132.0
docling-project docling-slim >= 2.95.0, < 2.132.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-522 The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CWE-201 The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability in Docling versions 2.95.0 to 2.132.0 involves the HTML image resource loader forwarding custom headers like API keys and cookies to remote image URLs specified in untrusted documents. This happens when enable_remote_fetch and fetch_images are enabled. The headers are not restricted to the original domain, allowing credentials to be exposed during cross-origin redirects.

Detection Guidance

Detecting this vulnerability requires checking if your Docling version is between 2.95.0 and 2.132.0 and if remote fetching with custom headers is enabled. Inspect the configuration files and logs for enable_remote_fetch=True and fetch_images=True settings.

Impact Analysis

An attacker could craft a document that triggers a redirect to a malicious server, causing your configured credentials to be sent to an unintended destination. This may lead to unauthorized access to sensitive resources or data leaks if the credentials are valid elsewhere.

Compliance Impact

This vulnerability could lead to unauthorized exposure of personal or sensitive data, violating GDPR's data protection principles or HIPAA's requirements for safeguarding protected health information. Compliance may be compromised if credentials are leaked and misused.

Mitigation Strategies

Upgrade Docling to version 2.132.0 or later. If upgrading is not possible, disable remote fetching by setting enable_remote_fetch=False or fetch_images=False in the configuration.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105742. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart