CVE-2026-105743
Received Received - Intake

Docling Remote Code Execution via DNS Rebinding

Vulnerability report for CVE-2026-105743, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.91.0 until 2.132.0, validate_url_safety in docling/backend/utils/image_resource_loader.py validates a hostname with a single IPv4 lookup and then allows the HTTP client to resolve and parse the original URL again, permitting DNS rebinding, mixed public and internal address records, and backslash authority parser disagreement to reach internal services. HTMLBackendOptions(render_page=True) also allows HTTP and HTTPS browser requests without validating their resolved destination. Exploitation requires remote fetching to be enabled, and response content is exposed only when it is decoded as an image or passively rendered in a page screenshot. This issue is fixed in 2.132.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
docling-project docling >= 2.91.0, < 2.132.0
docling-project docling-slim >= 2.91.0, < 2.132.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
CWE-367 The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability in Docling versions 2.91.0 to 2.132.0 involves improper URL validation in image_resource_loader.py. It allows DNS rebinding attacks and mixed address records by performing a single IPv4 lookup before permitting HTTP client resolution. This can lead to unauthorized access to internal services.

Detection Guidance

Detecting this vulnerability requires checking if your Docling version is between 2.91.0 and 2.132.0. Use commands like 'pip show docling' or 'docling --version' to check the installed version. If the version falls within the vulnerable range, the system is potentially affected.

Impact Analysis

An attacker could exploit this to access internal services or retrieve sensitive data if remote fetching is enabled. Exploitation requires fetching to be enabled and response content is only exposed when decoded as an image or rendered in a page screenshot.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized access to internal services through DNS rebinding and mixed address records. Exposed response content during image decoding or page rendering may lead to unintended data disclosure, violating confidentiality requirements under these regulations.

Mitigation Strategies

Upgrade Docling to version 2.132.0 or later immediately. Disable remote fetching if enabled and review HTMLBackendOptions settings to ensure no unvalidated HTTP/HTTPS requests are permitted. Monitor network traffic for unusual DNS rebinding or internal service access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105743. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart