Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105746— Docling: KServe v2 OCR engine does not enforce enable_remote_services

Quick assessment

Affected
docling-project docling
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Docling 通过解析多种格式并提供与生成式 AI 生态系统的集成,简化了文档处理流程。在版本 2.83.0 至 2.131.0 之间, 中定义的 类在向配置端点发送页面图像时,未检查 设置,即使调用方将该策略控制参数显式设置为 false。此外, 方法也未将该标志传递给 OCR 工厂函数,导致在依赖禁用远程服务的安全配置中,仍允许执行远程 OCR 处理。需要注意的是,该漏洞中的目标端点由调用方配置,而非由攻击者选择。此问题已在版本 2.131.0 中得到修复。

CVSS 2.2 · Low

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105746

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Docling: KServe v2 OCR engine does not enforce enable_remote_services
Source: CVE Program / CVE List V5
Vulnerability Description
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.83.0 until 2.131.0, the KServeV2OcrModel class defined in docling/models/stages/ocr/kserve_v2_ocr_model.py sends page images to its configured endpoint without checking the pipeline_options.enable_remote_services setting, even when the caller sets that policy control to false. The StandardPdfPipeline._make_ocr_model method also fails to pass the flag into the OCR factory, allowing remote OCR processing in configurations that rely on remote services being disabled. The destination is configured by the caller rather than selected by an attacker. This issue is fixed in 2.131.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
将资源暴露给错误范围
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
docling-project docling >= 2.83.0, < 2.131.0 -
docling-project docling-slim >= 2.83.0, < 2.131.0 -

II. Public POCs for CVE-2026-105746

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105746

请登录查看更多情报信息。

Other References for CVE-2026-105746 (4)

Same Patch Batch · docling-project · 2026-10-05 · 10 CVEs total

CVE-2026-105744 7.5 HIGH Docling: Arbitrary file read/write (and command execution when shell-escape is enabled) wh
CVE-2026-105751 6.9 MEDIUM Docling: Arbitrary local file read via draw:image xlink:href in the OpenDocument backend
CVE-2026-105745 6.7 MEDIUM Docling: Plugin entry points are imported before the allow_external_plugins check
CVE-2026-105749 6.5 MEDIUM Docling: Unbounded table rowspan/colspan in HTML, JATS, ODS and BoxNote backends causes CP
CVE-2026-105750 5.9 MEDIUM Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode
CVE-2026-105748 4.3 MEDIUM Docling: Crafted DoclingDocument JSON embeds local image files into converted output
CVE-2026-105747 4.3 MEDIUM Docling: METS-GBS archive member limit enforced after full member enumeration (memory exha
CVE-2026-105743 4.0 MEDIUM Docling: SSRF guard bypass in remote resource fetching (DNS rebinding / multi-record resol
CVE-2026-105742 3.7 LOW Docling: Configured HTTP headers sent to every remote image host named by a document

IV. Related Vulnerabilities

V. Comments for CVE-2026-105746

No comments yet


Leave a comment