CVE-2026-105742: Docling: Configured HTTP headers sent to every remote image host named by a document

Published Oct 5, 2026
·
Updated

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.95.0 until 2.132.0, the HTML image resource loader in docling/backend/utils/imageresourceloader.py forwards headers configured through the HTMLBackendOptions.headers setting to every remote image URL named by an untrusted document when enableremotefetch=True and fetchimages=True. The loader does not restrict those credentials to the source document's origin, allowing requests that carry custom headers such as API keys and cookies to follow cross-origin redirects and expose the caller's configured credentials to a document author. The default configuration is not affected because remote fetching and configured headers are required. This issue is fixed in 2.132.0.

Affected Software

1 affected component
pypi/docling>=2.95.0<2.132.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade docling to a version that resolves this vulnerability.

    Fixed in 2.132.0

Event History

Oct 5, 2026
CVE Published
via MITRE·09:21 PM
Data Sourced
via MITRE·09:21 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Deployments using Docling versions from 2.95.0 up to, but not including, 2.132.0 are exposed only when HTMLBackendOptions.headers is configured and both enable_remote_fetch=True and fetch_images=True. The default configuration is not affected.

2

What does an attacker need to exploit this issue?

An attacker needs to provide an untrusted document that names remote image URLs. When Docling processes that document with remote image fetching enabled, the attacker-controlled image host can receive the configured custom headers, including API keys or cookies.

3

Can redirects expand the exposure?

Yes. Requests carrying the configured headers can follow cross-origin redirects, potentially sending those credentials to additional remote hosts selected by the document author.

4

What should be done if upgrading is not immediately possible?

Disable remote fetching or image fetching for untrusted documents, or avoid configuring headers through HTMLBackendOptions.headers. These settings are all required for the exposure described.

5

How can I determine whether I am affected?

Check whether Docling is in the affected version range and whether your HTML processing configuration sets HTMLBackendOptions.headers while enable_remote_fetch and fetch_images are both enabled. Review processing of untrusted documents that can contain remote image URLs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203