CVE-2026-105745: Docling: Plugin entry points are imported before the allow_external_plugins check

Published Oct 5, 2026
·
Updated

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.27.0 until 2.131.0, Docling plugin factories in docling/models/factories/basefactory.py call loadsetuptoolsentrypoints() before applying the allowexternalplugins setting, so every module registered in the Docling entry-point group is imported even when external plugins are disabled. An installed third-party or compromised package can therefore execute import-time code when Docling starts, while the subsequent namespace filter misleadingly reports that the plugin was not loaded. This issue is fixed in 2.131.0.

Affected Software

1 affected component
pypi/docling>=2.27.0<2.131.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Docling to a version that resolves this vulnerability.

    Fixed in 2.131.0

Event History

Oct 5, 2026
CVE Published
via MITRE·09:29 PM
Data Sourced
via MITRE·09:29 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to import-time code execution?

Docling versions from 2.27.0 up to, but not including, 2.131.0 are affected when a third-party or compromised installed package registers an entry point in the Docling plugin group. The code can execute when Docling starts.

2

Does disabling external plugins prevent this issue?

No. In affected versions, Docling imports registered entry-point modules before it applies the allow_external_plugins check. The later filter may report that the plugin was not loaded even though its import-time code has already run.

3

What version resolves the issue?

Upgrade Docling to version 2.131.0 or later. The issue is fixed in 2.131.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203