DNS Rebinding Vulnerability in Docling Document Processing Software
CVE-2026-105743
What is CVE-2026-105743?
A DNS rebinding vulnerability exists in Docling's document processing framework, specifically affecting versions from 2.91.0 to 2.132.0. The issue arises from the validate_url_safety function, located in image_resource_loader.py, which uses a single IPv4 lookup for hostname validation. This approach allows for exploitation through DNS rebinding techniques, potentially exposing internal services when remote fetching is enabled. Issues with mixed public and internal address records, along with the backslash authority parser disagreement, compound the risk. Furthermore, the HTMLBackendOptions setting allows HTTP and HTTPS requests without sufficient validation of the resolved destinations. This vulnerability has been addressed in version 2.132.0.
Affected Version(s)
docling >= 2.91.0, < 2.132.0
docling-slim >= 2.91.0, < 2.132.0
