CVE-2026-105742: Docling: Configured HTTP headers sent to every remote image host named by a document
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.95.0 until 2.132.0, the HTML image resource loader in docling/backend/utils/imageresourceloader.py forwards headers configured through the HTMLBackendOptions.headers setting to every remote image URL named by an untrusted document when enableremotefetch=True and fetchimages=True. The loader does not restrict those credentials to the source document's origin, allowing requests that carry custom headers such as API keys and cookies to follow cross-origin redirects and expose the caller's configured credentials to a document author. The default configuration is not affected because remote fetching and configured headers are required. This issue is fixed in 2.132.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
doclingto a version that resolves this vulnerability.Fixed in 2.132.0
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments using Docling versions from 2.95.0 up to, but not including, 2.132.0 are exposed only when HTMLBackendOptions.headers is configured and both enable_remote_fetch=True and fetch_images=True. The default configuration is not affected.
What does an attacker need to exploit this issue?
An attacker needs to provide an untrusted document that names remote image URLs. When Docling processes that document with remote image fetching enabled, the attacker-controlled image host can receive the configured custom headers, including API keys or cookies.
Can redirects expand the exposure?
Yes. Requests carrying the configured headers can follow cross-origin redirects, potentially sending those credentials to additional remote hosts selected by the document author.
What should be done if upgrading is not immediately possible?
Disable remote fetching or image fetching for untrusted documents, or avoid configuring headers through HTMLBackendOptions.headers. These settings are all required for the exposure described.
How can I determine whether I am affected?
Check whether Docling is in the affected version range and whether your HTML processing configuration sets HTMLBackendOptions.headers while enable_remote_fetch and fetch_images are both enabled. Review processing of untrusted documents that can contain remote image URLs.