LowVulnerability
CVE-2026-105746: Docling remote OCR sends page images despite remote services disabled
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-105746
- Published
- Record updated
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.2%
Summary
Docling versions 2.83.0 through 2.131.0 send page images to a configured OCR endpoint through KServeV2OcrModel in docling/models/stages/ocr/kserve_v2_ocr_model.py, without checking pipeline_options.enable_remote_services, even when it is set to false. StandardPdfPipeline._make_ocr_model also fails to pass that flag into the OCR factory, so remote OCR runs in configurations that rely on remote services being disabled. The destination is set by the caller, not chosen by an attacker.
Mitigation
Fixed in 2.131.0.
Related items
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database