Docling 通过解析多种格式并提供与生成式 AI 生态系统的集成,简化了文档处理流程。在版本 2.83.0 至 2.131.0 之间, 中定义的 类在向配置端点发送页面图像时,未检查 设置,即使调用方将该策略控制参数显式设置为 false。此外, 方法也未将该标志传递给 OCR 工厂函数,导致在依赖禁用远程服务的安全配置中,仍允许执行远程 OCR 处理。需要注意的是,该漏洞中的目标端点由调用方配置,而非由攻击者选择。此问题已在版本 2.131.0 中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| docling-project | docling | >= 2.83.0, < 2.131.0 | - |
|
| docling-project | docling-slim | >= 2.83.0, < 2.131.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105744 | 7.5 HIGH | Docling: Arbitrary file read/write (and command execution when shell-escape is enabled) wh |
| CVE-2026-105751 | 6.9 MEDIUM | Docling: Arbitrary local file read via draw:image xlink:href in the OpenDocument backend |
| CVE-2026-105745 | 6.7 MEDIUM | Docling: Plugin entry points are imported before the allow_external_plugins check |
| CVE-2026-105749 | 6.5 MEDIUM | Docling: Unbounded table rowspan/colspan in HTML, JATS, ODS and BoxNote backends causes CP |
| CVE-2026-105750 | 5.9 MEDIUM | Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode |
| CVE-2026-105748 | 4.3 MEDIUM | Docling: Crafted DoclingDocument JSON embeds local image files into converted output |
| CVE-2026-105747 | 4.3 MEDIUM | Docling: METS-GBS archive member limit enforced after full member enumeration (memory exha |
| CVE-2026-105743 | 4.0 MEDIUM | Docling: SSRF guard bypass in remote resource fetching (DNS rebinding / multi-record resol |
| CVE-2026-105742 | 3.7 LOW | Docling: Configured HTTP headers sent to every remote image host named by a document |
No comments yet