Skip to content
MediumVulnerability

CVE-2026-105745: Docling plugin loading runs entry-point modules when plugins are disabled

Identifier
CVE-2026-105745
Published
Record updated
View JSON
Affected
  • docling >= 2.27.0, < 2.131.0
  • docling-slim >= 2.92.0, < 2.131.0
Fixed in
2.131.0
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.1%

Summary

Docling, a document processing library, runs plugin factories in docling/models/factories/base_factory.py that call load_setuptools_entrypoints() before checking allow_external_plugins. From 2.27.0 until 2.131.0, every module in the Docling entry-point group is imported even when external plugins are disabled. An installed third-party or compromised package can therefore run import-time code when Docling starts, and the namespace filter wrongly reports that the plugin was not loaded.

Mitigation

Fixed in 2.131.0.