Sceawere

Vulnerability Detail

CVE-2026-105746UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Docling Remote OCR Policy Bypass

Vulnerability Metadata

Severity
Low
Score / CVSS
2.2
Creation Date
1h ago
Vendor
docling-project
Product
docling
Attack Type
CWE-668: Exposure of Resource to Wrong Sphere
Vector String
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.83.0 until 2.131.0, the KServeV2OcrModel class defined in docling/models/stages/ocr/kserve_v2_ocr_model.py sends page images to its configured endpoint without checking the pipeline_options.enable_remote_services setting, even when the caller sets that policy control to false. The StandardPdfPipeline._make_ocr_model method also fails to pass the flag into the OCR factory, allowing remote OCR processing in configurations that rely on remote services being disabled. The destination is configured by the caller rather than selected by an attacker. This issue is fixed in 2.131.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "2.2",
  "pubDate": "2026-10-05T22:16:57.480Z",
  "pubdate": "2026-10-05T22:16:57.480Z",
  "executiveSummary": "Docling versions 2.83.0 through 2.131.0 contain a security flaw involving the improper enforcement of policy-based service restrictions during document processing.\nThe vulnerability allows for the unauthorized transmission of document page images to remote KServe-based OCR endpoints, even when the user explicitly disables remote services via the 'pipeline_options.enable_remote_services' configuration.\nThis represents a failure in the security control logic, leading to a bypass of privacy and data exfiltration protections intended to restrict document data to local processing only.\nThe vulnerability affects users relying on Docling for sensitive data processing where compliance or security policies mandate that document imagery must remain within local environments.\nWhile the destination endpoint is determined by the caller rather than the attacker, the bypass allows the processing of sensitive document data in contexts where the user expects an air-gapped or localized operation.\nThis vulnerability does not facilitate arbitrary code execution but effectively subverts architectural data governance requirements.",
  "technicalDetails": "The root cause of the vulnerability lies in a logic failure within the 'KServeV2OcrModel' class located in 'docling/models/stages/ocr/kserve_v2_ocr_model.py' and the factory orchestration logic in 'StandardPdfPipeline._make_ocr_model'.\nIn affected versions, the 'KServeV2OcrModel' class initiates network requests to a configured KServe endpoint to perform OCR tasks on page images without validating the 'pipeline_options.enable_remote_services' configuration parameter.\nThe 'StandardPdfPipeline._make_ocr_model' factory method is responsible for instantiating the OCR model but fails to propagate the 'enable_remote_services' flag into the factory parameters. As a result, the instance of 'KServeV2OcrModel' is initialized as if remote services are permitted, regardless of the global configuration state.\nThe attack flow occurs when a user or application attempts to process a PDF document with the expectation that data will not be transmitted externally. Because the flag check is bypassed, the component proceeds to serialize and transmit page imagery via HTTP/REST to the remote endpoint specified in the configuration.\nEven if the caller explicitly sets 'enable_remote_services' to 'false', the application continues to perform network-based OCR operations. This bypasses the intended boundary of data processing, potentially resulting in the exposure of sensitive document contents to external network infrastructure.\nThe exploitation does not require authentication or specific privilege levels from an attacker, as the vulnerability is inherent to the logic flow of the library itself. The impact is primarily a violation of data sovereignty and confidentiality policies, as the software fails to respect the 'do-not-transmit' instructions defined in the pipeline configuration.\nPost-exploitation impact is limited to the unauthorized external transit of data to a configured endpoint. Because the endpoint destination is defined by the user's current configuration, this flaw behaves more as a configuration enforcement failure than a remote code execution vector, yet it remains a significant risk for environments handling PII or sensitive proprietary documents."
}
CVE-2026-105746: Docling Remote OCR Policy Bypass (LOW Severity, CVSS: 2.2) | Sceawere