InputFormat.JSON_DOCLING Vulnerability in Docling Document Processing by Docling
CVE-2026-105748

4.3MEDIUM

Key Information:

Vendor
CVE Published:
5 October 2026

What is CVE-2026-105748?

In versions 2.16.0 to 2.131.0 of Docling, the InputFormat.JSON_DOCLING backend lacks proper validation for serialized DoclingDocument inputs. Specifically, it fails to reject image references that contain local paths or file URIs. When documents are processed with ImageRefMode.EMBEDDED, methods like DoclingDocument._with_embedded_pictures and ImageRef.pil_image can accidentally expose readable image bytes through Markdown or HTML outputs. The vulnerability allows for potential exposure of the existence of specific file paths based on the different decoding behavior of files that the Pillow library can process as images. Although direct untrusted loading via docling-core is not addressed in this fix, the issue has been resolved in version 2.131.0.

Affected Version(s)

docling >= 2.16.0, < 2.131.0

docling-slim >= 2.16.0, < 2.131.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.