HTML Image Resource Loader Vulnerability in Docling by the Docling Project
CVE-2026-105742

3.7LOW

Key Information:

Vendor
CVE Published:
5 October 2026

What is CVE-2026-105742?

The HTML image resource loader in versions 2.95.0 through 2.132.0 of Docling is susceptible to a cross-origin credential exposure vulnerability. When configured to enable remote fetching of images and configured headers, the loader forwards these headers to all remote image URLs specified by untrusted documents. This oversight allows malicious actors to exploit these headers, potentially exposing sensitive information such as API keys and cookies when documents redirect to untrusted origins. The default configuration does not pose a risk since remote fetching and custom headers are not enabled. This vulnerability has been resolved in version 2.132.0.

Affected Version(s)

docling >= 2.95.0, < 2.132.0

docling-slim >= 2.95.0, < 2.132.0

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.