HTML Image Resource Loader Vulnerability in Docling by the Docling Project
CVE-2026-105742
3.7LOW
What is CVE-2026-105742?
The HTML image resource loader in versions 2.95.0 through 2.132.0 of Docling is susceptible to a cross-origin credential exposure vulnerability. When configured to enable remote fetching of images and configured headers, the loader forwards these headers to all remote image URLs specified by untrusted documents. This oversight allows malicious actors to exploit these headers, potentially exposing sensitive information such as API keys and cookies when documents redirect to untrusted origins. The default configuration does not pose a risk since remote fetching and custom headers are not enabled. This vulnerability has been resolved in version 2.132.0.
Affected Version(s)
docling >= 2.95.0, < 2.132.0
docling-slim >= 2.95.0, < 2.132.0
