Docling 通过解析多种文档格式并提供与生成式 AI 生态系统的集成,简化了文档处理流程。在版本 2.94.0 至 2.132.0 之间,当用户选择使用 时,系统会调用 来编译不受信任的 TikZ 内容体及文档导言区(preamble),且未对 TeX 文件原语(包括 和 )进行限制。恶意构造的输入可读取转换器可访问的文件,并创建或覆盖可写文件;若同时启用 选项,还会允许通过 TeX 执行 Shell 命令。默认配置(未启用 Tectonic 渲染)不受此漏洞影响。该漏洞已在版本 2.132.0 中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| docling-project | docling | >= 2.94.0, < 2.132.0 | - |
|
| docling-project | docling-slim | >= 2.94.0, < 2.132.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105751 | 6.9 MEDIUM | Docling: Arbitrary local file read via draw:image xlink:href in the OpenDocument backend |
| CVE-2026-105745 | 6.7 MEDIUM | Docling: Plugin entry points are imported before the allow_external_plugins check |
| CVE-2026-105749 | 6.5 MEDIUM | Docling: Unbounded table rowspan/colspan in HTML, JATS, ODS and BoxNote backends causes CP |
| CVE-2026-105750 | 5.9 MEDIUM | Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode |
| CVE-2026-105748 | 4.3 MEDIUM | Docling: Crafted DoclingDocument JSON embeds local image files into converted output |
| CVE-2026-105747 | 4.3 MEDIUM | Docling: METS-GBS archive member limit enforced after full member enumeration (memory exha |
| CVE-2026-105743 | 4.0 MEDIUM | Docling: SSRF guard bypass in remote resource fetching (DNS rebinding / multi-record resol |
| CVE-2026-105742 | 3.7 LOW | Docling: Configured HTTP headers sent to every remote image host named by a document |
| CVE-2026-105746 | 2.2 LOW | Docling: KServe v2 OCR engine does not enforce enable_remote_services |
No comments yet