Remote Service Configuration Flaw in Docling by Docling Project
CVE-2026-105746

2.2LOW

Key Information:

Vendor
CVE Published:
5 October 2026

What is CVE-2026-105746?

A significant vulnerability exists in Docling's KServeV2OcrModel class, which processes images without properly enforcing remote service settings. This oversight allows remote OCR processing to occur even when the configuration disables such services, leading to potential security exposures. Implementing updates in version 2.131.0 addresses this issue, ensuring that the pipeline options are respected.

Affected Version(s)

docling >= 2.83.0, < 2.131.0

docling-slim >= 2.83.0, < 2.131.0

References

CVSS V3.1

Score:
2.2
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.