Docling 通过解析多种文档格式并提供与生成式 AI 生态系统的集成,简化了文档处理流程。在版本 2.16.0 至 2.131.0 之间,Docling 的 后端(位于 )在验证序列化的 DoclingDocument 输入时,未拒绝包含本地路径或文件 URI 的图片引用。当文档通过 模式进行增强或导出时, 和 方法会打开这些引用,并将可读的图像字节嵌入到 Markdown 或 HTML 输出中。披露范围限于 Pillow 能够解码为图像的格式,但由于不同解码行为可能揭示路径是否存在,这也可能导致信息泄露。通过
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| docling-project | docling | >= 2.16.0, < 2.131.0 | - |
|
| docling-project | docling-slim | >= 2.16.0, < 2.131.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105744 | 7.5 HIGH | Docling: Arbitrary file read/write (and command execution when shell-escape is enabled) wh |
| CVE-2026-105751 | 6.9 MEDIUM | Docling: Arbitrary local file read via draw:image xlink:href in the OpenDocument backend |
| CVE-2026-105745 | 6.7 MEDIUM | Docling: Plugin entry points are imported before the allow_external_plugins check |
| CVE-2026-105749 | 6.5 MEDIUM | Docling: Unbounded table rowspan/colspan in HTML, JATS, ODS and BoxNote backends causes CP |
| CVE-2026-105750 | 5.9 MEDIUM | Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode |
| CVE-2026-105747 | 4.3 MEDIUM | Docling: METS-GBS archive member limit enforced after full member enumeration (memory exha |
| CVE-2026-105743 | 4.0 MEDIUM | Docling: SSRF guard bypass in remote resource fetching (DNS rebinding / multi-record resol |
| CVE-2026-105742 | 3.7 LOW | Docling: Configured HTTP headers sent to every remote image host named by a document |
| CVE-2026-105746 | 2.2 LOW | Docling: KServe v2 OCR engine does not enforce enable_remote_services |
No comments yet