CVE-2026-105746
Received Received - Intake

Remote OCR Processing Bypass in Docling

Vulnerability report for CVE-2026-105746, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.83.0 until 2.131.0, the KServeV2OcrModel class defined in docling/models/stages/ocr/kserve_v2_ocr_model.py sends page images to its configured endpoint without checking the pipeline_options.enable_remote_services setting, even when the caller sets that policy control to false. The StandardPdfPipeline._make_ocr_model method also fails to pass the flag into the OCR factory, allowing remote OCR processing in configurations that rely on remote services being disabled. The destination is configured by the caller rather than selected by an attacker. This issue is fixed in 2.131.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
docling-project docling >= 2.83.0, < 2.131.0
docling-project docling-slim >= 2.83.0, < 2.131.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-693 The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
CWE-668 The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability in Docling versions 2.83.0 to 2.131.0 allows page images to be sent to a configured endpoint for OCR processing even when remote services are disabled via pipeline_options.enable_remote_services. The KServeV2OcrModel class and StandardPdfPipeline._make_ocr_model method fail to respect this policy control, potentially enabling unintended remote processing.

Detection Guidance

The vulnerability involves Docling versions 2.83.0 to 2.131.0 sending page images to remote endpoints despite pipeline_options.enable_remote_services being set to false. Check Docling version with pip show docling. Monitor network traffic for unexpected outbound connections to OCR endpoints.

Impact Analysis

This vulnerability may lead to unintended exposure of sensitive document content to remote endpoints if the system is configured to disable remote services. It could result in data leaks or unauthorized processing of documents.

Compliance Impact

The vulnerability could violate data protection requirements under GDPR or HIPAA by allowing unauthorized remote processing or transmission of sensitive documents, potentially leading to non-compliance with data handling policies.

Mitigation Strategies

Upgrade Docling to version 2.131.0 or later. Verify pipeline_options.enable_remote_services is set to false and enforced. Review network configurations to block unauthorized OCR service connections.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105746. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart