Sceawere
Vulnerability Detail
CVE-2026-105746UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Docling Remote OCR Policy Bypass
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 2.2
- Creation Date
- 1h ago
- Vendor
- docling-project
- Product
- docling
- Attack Type
- CWE-668: Exposure of Resource to Wrong Sphere
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.83.0 until 2.131.0, the KServeV2OcrModel class defined in docling/models/stages/ocr/kserve_v2_ocr_model.py sends page images to its configured endpoint without checking the pipeline_options.enable_remote_services setting, even when the caller sets that policy control to false. The StandardPdfPipeline._make_ocr_model method also fails to pass the flag into the OCR factory, allowing remote OCR processing in configurations that rely on remote services being disabled. The destination is configured by the caller rather than selected by an attacker. This issue is fixed in 2.131.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "2.2",
"pubDate": "2026-10-05T22:16:57.480Z",
"pubdate": "2026-10-05T22:16:57.480Z",
"executiveSummary": "Docling versions 2.83.0 through 2.131.0 contain a security flaw involving the improper enforcement of policy-based service restrictions during document processing.\nThe vulnerability allows for the unauthorized transmission of document page images to remote KServe-based OCR endpoints, even when the user explicitly disables remote services via the 'pipeline_options.enable_remote_services' configuration.\nThis represents a failure in the security control logic, leading to a bypass of privacy and data exfiltration protections intended to restrict document data to local processing only.\nThe vulnerability affects users relying on Docling for sensitive data processing where compliance or security policies mandate that document imagery must remain within local environments.\nWhile the destination endpoint is determined by the caller rather than the attacker, the bypass allows the processing of sensitive document data in contexts where the user expects an air-gapped or localized operation.\nThis vulnerability does not facilitate arbitrary code execution but effectively subverts architectural data governance requirements.",
"technicalDetails": "The root cause of the vulnerability lies in a logic failure within the 'KServeV2OcrModel' class located in 'docling/models/stages/ocr/kserve_v2_ocr_model.py' and the factory orchestration logic in 'StandardPdfPipeline._make_ocr_model'.\nIn affected versions, the 'KServeV2OcrModel' class initiates network requests to a configured KServe endpoint to perform OCR tasks on page images without validating the 'pipeline_options.enable_remote_services' configuration parameter.\nThe 'StandardPdfPipeline._make_ocr_model' factory method is responsible for instantiating the OCR model but fails to propagate the 'enable_remote_services' flag into the factory parameters. As a result, the instance of 'KServeV2OcrModel' is initialized as if remote services are permitted, regardless of the global configuration state.\nThe attack flow occurs when a user or application attempts to process a PDF document with the expectation that data will not be transmitted externally. Because the flag check is bypassed, the component proceeds to serialize and transmit page imagery via HTTP/REST to the remote endpoint specified in the configuration.\nEven if the caller explicitly sets 'enable_remote_services' to 'false', the application continues to perform network-based OCR operations. This bypasses the intended boundary of data processing, potentially resulting in the exposure of sensitive document contents to external network infrastructure.\nThe exploitation does not require authentication or specific privilege levels from an attacker, as the vulnerability is inherent to the logic flow of the library itself. The impact is primarily a violation of data sovereignty and confidentiality policies, as the software fails to respect the 'do-not-transmit' instructions defined in the pipeline configuration.\nPost-exploitation impact is limited to the unauthorized external transit of data to a configured endpoint. Because the endpoint destination is defined by the user's current configuration, this flaw behaves more as a configuration enforcement failure than a remote code execution vector, yet it remains a significant risk for environments handling PII or sensitive proprietary documents."
}