Docling 通过解析多种文档格式并提供与生成式 AI 生态系统的集成,简化了文档处理流程。在版本 2.107.0 至 2.120.3 之间, 在文档归档中未找到所引用的部分时,会直接使用 元素的 属性值作为文件系统路径。 函数在未进行协议(scheme)校验、未限制提取目录、且未采用其他后端所使用的 设置的情况下,读取了该由攻击者控制的路径。Pillow 能够解码为图像的只读文件会被嵌入到转换输出中,而其他已有路径也可通过尝试读取操作被区分出来。此问题已在版本 2.120.3 中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| docling-project | docling | >= 2.107.0, < 2.120.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105744 | 7.5 HIGH | Docling: Arbitrary file read/write (and command execution when shell-escape is enabled) wh |
| CVE-2026-105745 | 6.7 MEDIUM | Docling: Plugin entry points are imported before the allow_external_plugins check |
| CVE-2026-105749 | 6.5 MEDIUM | Docling: Unbounded table rowspan/colspan in HTML, JATS, ODS and BoxNote backends causes CP |
| CVE-2026-105750 | 5.9 MEDIUM | Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode |
| CVE-2026-105748 | 4.3 MEDIUM | Docling: Crafted DoclingDocument JSON embeds local image files into converted output |
| CVE-2026-105747 | 4.3 MEDIUM | Docling: METS-GBS archive member limit enforced after full member enumeration (memory exha |
| CVE-2026-105743 | 4.0 MEDIUM | Docling: SSRF guard bypass in remote resource fetching (DNS rebinding / multi-record resol |
| CVE-2026-105742 | 3.7 LOW | Docling: Configured HTTP headers sent to every remote image host named by a document |
| CVE-2026-105746 | 2.2 LOW | Docling: KServe v2 OCR engine does not enforce enable_remote_services |
No comments yet