Sceawere

Vulnerability Detail

CVE-2026-105742UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Docling Credential Exposure Vulnerability

Vulnerability Metadata

Severity
Low
Score / CVSS
3.7
Creation Date
1h ago
Vendor
docling-project
Product
docling
Attack Type
CWE-201: Insertion of Sensitive Information Into Sent Data
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.95.0 until 2.132.0, the HTML image resource loader in docling/backend/utils/image_resource_loader.py forwards headers configured through the HTMLBackendOptions.headers setting to every remote image URL named by an untrusted document when enable_remote_fetch=True and fetch_images=True. The loader does not restrict those credentials to the source document's origin, allowing requests that carry custom headers such as API keys and cookies to follow cross-origin redirects and expose the caller's configured credentials to a document author. The default configuration is not affected because remote fetching and configured headers are required. This issue is fixed in 2.132.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.7",
  "pubDate": "2026-10-05T22:16:56.867Z",
  "pubdate": "2026-10-05T22:16:56.867Z",
  "executiveSummary": "The Docling library is affected by a cross-origin credential leakage vulnerability within its HTML image resource loader component.\nThe flaw allows unauthorized exposure of sensitive headers—such as API keys or cookies—when the library is configured to fetch remote images from untrusted documents.\nThis vulnerability exists in Docling versions 2.95.0 through 2.131.0 when both enable_remote_fetch and fetch_images are explicitly enabled by the user.\nThe primary risk involves an attacker crafting a document that triggers the library to follow cross-origin redirects, causing the library to transmit custom headers to an attacker-controlled endpoint.\nThis represents a significant security concern for applications that utilize Docling to parse untrusted user-submitted documents while using authenticated sessions or privileged API headers.",
  "technicalDetails": "The vulnerability resides in the docling/backend/utils/image_resource_loader.py file, specifically within the HTML image resource loading logic.\nThe root cause is the failure to enforce origin-based access control when applying headers defined in HTMLBackendOptions.headers. When the library is instructed to process remote resources, it indiscriminately forwards these configured headers to any URL defined within the document's image tags.\nBecause the loader does not restrict header transmission to the original source domain, the library will persist these sensitive headers even when the request follows cross-origin redirects. An attacker can host a malicious document containing an image URL that points to an attacker-controlled server. Upon parsing this document, Docling initiates a request to the attacker's server, attaching the potentially sensitive headers configured in the library's environment.\nThe attack flow proceeds as follows: 1) The user configures Docling with sensitive headers (e.g., Authorization tokens or session cookies) to facilitate authenticated access to internal image assets. 2) An attacker submits a crafted document containing an image URL targeting an adversary-controlled server. 3) The library attempts to fetch the image. 4) The attacker's server receives the request, capturing the sensitive headers forwarded by the library. 5) If the request involves a redirect, the library continues to transmit the headers to the redirected destination, facilitating the exfiltration of credentials to arbitrary third-party infrastructure.\nThe vulnerability is active only when enable_remote_fetch and fetch_images are both set to True; the default configuration of the library is not inherently vulnerable. The scope of the issue spans from version 2.95.0 through 2.131.0. The impact of successful exploitation includes the unauthorized capture of authentication credentials, which may be leveraged for lateral movement or data exfiltration within the context of the environment where Docling is deployed."
}
CVE-2026-105742: Docling Credential Exposure Vulnerability (LOW Severity, CVSS: 3.7) | Sceawere