Sceawere

Vulnerability Detail

CVE-2026-105743UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Docling Server-Side Request Forgery

Vulnerability Metadata

Severity
Medium
Score / CVSS
4
Creation Date
1h ago
Vendor
docling-project
Product
docling
Attack Type
CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.91.0 until 2.132.0, validate_url_safety in docling/backend/utils/image_resource_loader.py validates a hostname with a single IPv4 lookup and then allows the HTTP client to resolve and parse the original URL again, permitting DNS rebinding, mixed public and internal address records, and backslash authority parser disagreement to reach internal services. HTMLBackendOptions(render_page=True) also allows HTTP and HTTPS browser requests without validating their resolved destination. Exploitation requires remote fetching to be enabled, and response content is exposed only when it is decoded as an image or passively rendered in a page screenshot. This issue is fixed in 2.132.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.0",
  "pubDate": "2026-10-05T22:16:57.030Z",
  "pubdate": "2026-10-05T22:16:57.030Z",
  "executiveSummary": "The Docling library is vulnerable to a Server-Side Request Forgery (SSRF) flaw due to insufficient validation of resolved destination addresses. This vulnerability impacts Docling versions 2.91.0 through 2.132.0. The security failure occurs within the document processing pipeline where image resource loading and page rendering components fail to enforce strict network-level controls on outbound HTTP/HTTPS requests.\nThe flaw stems from a time-of-check to time-of-use (TOCTOU) discrepancy: the validate_url_safety function performs an initial IPv4 hostname lookup, but the subsequent HTTP client resolution and parsing stages permit the traversal of disparate, potentially internal, network destinations. Attackers can leverage this to bypass security boundaries, potentially accessing internal services, private endpoints, or local network resources that should be inaccessible from the processing host.\nExploitation requires remote fetching to be enabled and is primarily contingent on the ability to control input URLs provided to the system. While the exfiltration of arbitrary content is constrained by the requirement that responses be processed as images or rendered via browser screenshots, the impact remains significant as it facilitates unauthorized interaction with internal infrastructure, potentially leading to information disclosure or further internal network reconnaissance.",
  "technicalDetails": "The root cause of this vulnerability lies in the improper implementation of URL validation within docling/backend/utils/image_resource_loader.py and the subsequent handling of requests by the HTTP client. The function validate_url_safety conducts a singular IPv4 lookup to perform safety checks; however, this validation is decoupled from the actual execution of the network request. Once the validation check is passed, the HTTP client performs its own independent DNS resolution and URL parsing.\nThis architectural flaw creates a vulnerability to DNS rebinding attacks, where an attacker resolves a domain to a 'safe' IP address initially, but returns a malicious, internal, or restricted IP address during the actual request execution. Furthermore, the discrepancy between the initial validator and the HTTP client regarding backslash authority parsing allows for the obfuscation of the intended target, bypassing checks intended to block internal addresses.\nAdditionally, HTMLBackendOptions(render_page=True) contributes to the attack surface by initiating HTTP/HTTPS browser requests without validating the final resolved destination. This allows the renderer to communicate with arbitrary internal destinations that the initial validator may have deemed safe based on the initial host resolution.\nThe attack flow proceeds as follows: First, an attacker provides a URL for a remote resource that is designed to evade the initial IPv4-based check. Second, the validate_url_safety mechanism performs its check against a benign target. Third, the HTTP client or the page renderer initiates a connection to the provided URL. Fourth, the attacker uses techniques such as DNS rebinding or authority parsing exploitation to force the client to connect to an internal service or an unauthorized host. Fifth, the application processes the response—either by attempting to decode it as an image or by taking a screenshot of the rendered page—thereby providing the attacker with visibility into the content returned by the internal service. This process effectively permits the attacker to bypass network segmentation and interact with services within the infrastructure of the host environment, leading to potential data exfiltration or internal service exploitation."
}
CVE-2026-105743: Docling Server-Side Request Forgery (MEDIUM Severity, CVSS: 4.0) | Sceawere