Docling 通过解析多种文档格式并提供与生成式 AI 生态系统的集成,简化了文档处理流程。在版本 2.91.0 至 2.132.0 之间, 中的 函数仅通过单次 IPv4 地址解析来验证主机名,随后允许 HTTP 客户端重新解析并处理原始 URL,从而导致 DNS 重绑定攻击、公共地址与内部地址记录混合利用,以及反斜杠权威部分(backslash authority)解析器分歧等问题可能访问到内部服务。此外,使用 配置时,系统允许发起 HTTP 和 HTTPS 的浏览器请求,但未对其最终解析的目标地址进行验证。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| docling-project | docling | >= 2.91.0, < 2.132.0 | - |
|
| docling-project | docling-slim | >= 2.91.0, < 2.132.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105744 | 7.5 HIGH | Docling: Arbitrary file read/write (and command execution when shell-escape is enabled) wh |
| CVE-2026-105751 | 6.9 MEDIUM | Docling: Arbitrary local file read via draw:image xlink:href in the OpenDocument backend |
| CVE-2026-105745 | 6.7 MEDIUM | Docling: Plugin entry points are imported before the allow_external_plugins check |
| CVE-2026-105749 | 6.5 MEDIUM | Docling: Unbounded table rowspan/colspan in HTML, JATS, ODS and BoxNote backends causes CP |
| CVE-2026-105750 | 5.9 MEDIUM | Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode |
| CVE-2026-105748 | 4.3 MEDIUM | Docling: Crafted DoclingDocument JSON embeds local image files into converted output |
| CVE-2026-105747 | 4.3 MEDIUM | Docling: METS-GBS archive member limit enforced after full member enumeration (memory exha |
| CVE-2026-105742 | 3.7 LOW | Docling: Configured HTTP headers sent to every remote image host named by a document |
| CVE-2026-105746 | 2.2 LOW | Docling: KServe v2 OCR engine does not enforce enable_remote_services |
No comments yet