Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105743— Docling: SSRF guard bypass in remote resource fetching (DNS rebinding / multi-record resolution; no IP validation in HTML render mode)

Quick assessment

Affected
docling-project docling
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Docling 通过解析多种文档格式并提供与生成式 AI 生态系统的集成,简化了文档处理流程。在版本 2.91.0 至 2.132.0 之间, 中的 函数仅通过单次 IPv4 地址解析来验证主机名,随后允许 HTTP 客户端重新解析并处理原始 URL,从而导致 DNS 重绑定攻击、公共地址与内部地址记录混合利用,以及反斜杠权威部分(backslash authority)解析器分歧等问题可能访问到内部服务。此外,使用 配置时,系统允许发起 HTTP 和 HTTPS 的浏览器请求,但未对其最终解析的目标地址进行验证。

CVSS 4.0 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105743

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Docling: SSRF guard bypass in remote resource fetching (DNS rebinding / multi-record resolution; no IP validation in HTML render mode)
Source: CVE Program / CVE List V5
Vulnerability Description
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.91.0 until 2.132.0, validate_url_safety in docling/backend/utils/image_resource_loader.py validates a hostname with a single IPv4 lookup and then allows the HTTP client to resolve and parse the original URL again, permitting DNS rebinding, mixed public and internal address records, and backslash authority parser disagreement to reach internal services. HTMLBackendOptions(render_page=True) also allows HTTP and HTTPS browser requests without validating their resolved destination. Exploitation requires remote fetching to be enabled, and response content is exposed only when it is decoded as an image or passively rendered in a page screenshot. This issue is fixed in 2.132.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
检查时间与使用时间(TOCTOU)的竞争条件
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
docling-project docling >= 2.91.0, < 2.132.0 -
docling-project docling-slim >= 2.91.0, < 2.132.0 -

II. Public POCs for CVE-2026-105743

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105743

请登录查看更多情报信息。

Other References for CVE-2026-105743 (4)

Same Patch Batch · docling-project · 2026-10-05 · 10 CVEs total

CVE-2026-105744 7.5 HIGH Docling: Arbitrary file read/write (and command execution when shell-escape is enabled) wh
CVE-2026-105751 6.9 MEDIUM Docling: Arbitrary local file read via draw:image xlink:href in the OpenDocument backend
CVE-2026-105745 6.7 MEDIUM Docling: Plugin entry points are imported before the allow_external_plugins check
CVE-2026-105749 6.5 MEDIUM Docling: Unbounded table rowspan/colspan in HTML, JATS, ODS and BoxNote backends causes CP
CVE-2026-105750 5.9 MEDIUM Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode
CVE-2026-105748 4.3 MEDIUM Docling: Crafted DoclingDocument JSON embeds local image files into converted output
CVE-2026-105747 4.3 MEDIUM Docling: METS-GBS archive member limit enforced after full member enumeration (memory exha
CVE-2026-105742 3.7 LOW Docling: Configured HTTP headers sent to every remote image host named by a document
CVE-2026-105746 2.2 LOW Docling: KServe v2 OCR engine does not enforce enable_remote_services

IV. Related Vulnerabilities

V. Comments for CVE-2026-105743

No comments yet


Leave a comment