DNS Rebinding Vulnerability in Docling Document Processing Software
CVE-2026-105743

4MEDIUM

Key Information:

Vendor
CVE Published:
5 October 2026

What is CVE-2026-105743?

A DNS rebinding vulnerability exists in Docling's document processing framework, specifically affecting versions from 2.91.0 to 2.132.0. The issue arises from the validate_url_safety function, located in image_resource_loader.py, which uses a single IPv4 lookup for hostname validation. This approach allows for exploitation through DNS rebinding techniques, potentially exposing internal services when remote fetching is enabled. Issues with mixed public and internal address records, along with the backslash authority parser disagreement, compound the risk. Furthermore, the HTMLBackendOptions setting allows HTTP and HTTPS requests without sufficient validation of the resolved destinations. This vulnerability has been addressed in version 2.132.0.

Affected Version(s)

docling >= 2.91.0, < 2.132.0

docling-slim >= 2.91.0, < 2.132.0

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.