{"data":{"id":"ff5cbe03-9623-4ad8-bde3-d601d741bddf","title":"CVE-2026-105743: Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI…","summary":"Docling, from 2.91.0 through 2.132.0, has a flaw in validate_url_safety (docling/backend/utils/image_resource_loader.py). It checks a hostname with a single IPv4 lookup, then lets the HTTP client resolve the original URL again, which allows DNS rebinding and mixed public and internal address records to reach internal services. HTMLBackendOptions(render_page=True) also permits HTTP and HTTPS browser requests without validating their resolved destination. Exploitation requires remote fetching to be enabled, and response content is exposed only when decoded as an image or passively rendered in a page screenshot.","solution":"Fixed in 2.132.0.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105743","publishedAt":"2026-10-05T22:16:57.030Z","cveId":"CVE-2026-105743","cweIds":["CWE-367","CWE-918"],"cvssScore":"4","cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":["docling@>= 2.91.0, < 2.132.0 (fixed: 2.132.0)","docling-slim@>= 2.92.0, < 2.132.0 (fixed: 2.132.0)"],"affectedPackageNames":["docling","docling-slim"],"affectedVendors":[],"affectedVendorsRaw":["Docling"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N","attackVector":"network","attackComplexity":"high","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.0019,"epssCheckedAt":"2026-10-10T02:59:17.261Z","kevDateAdded":null,"advisoryAliases":["GHSA-pc36-qwjq-x68c"],"affectedPackagesSource":"ghsa","affectedPackagesCheckedAt":"2026-10-10T03:42:55.567Z","patchAvailable":true,"disclosureDate":"2026-10-05T22:16:57.030Z","capecIds":["CAPEC-27","CAPEC-664"],"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality"],"aiComponentTargeted":"rag","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":["AML.T0010"]}}