DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-105742: CVE-2026-105742: Sensitive Custom Header Leakage in Docling Image Resource Loader

CVE-2026-105742: Sensitive Custom Header Leakage in Docling Image Resource Loader

Vulnerability ID: CVE-2026-105742
CVSS Score: 3.7
Published: 2026-10-07

A technical analysis of CVE-2026-105742 (GHSA-p3fw-7699-7926), a sensitive information disclosure vulnerability in the Docling document processing library. Vulnerable versions of Docling indiscriminately forward custom HTTP headers, such as authentication tokens, to arbitrary third-party origins and during cross-origin redirects while fetching remote image assets from untrusted HTML and EPUB documents.

TL;DR

Docling versions before 2.132.0 leak custom HTTP authentication headers configured in HTMLBackendOptions.headers to arbitrary third-party domains when retrieving remote images embedded in processed documents or during cross-origin redirects.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-201 / CWE-522
  • Attack Vector: Network (AV:N)
  • CVSS Severity: 3.7 (Low)
  • EPSS Score: 0.00218 (Percentile: 11.24%)
  • Exploit Status: Proof-of-Concept
  • CISA KEV Status: Not Listed

Affected Systems

  • docling
  • docling-slim
  • docling: >= 2.95.0, < 2.132.0 (Fixed in: 2.132.0)
  • docling-slim: >= 2.95.0, < 2.132.0 (Fixed in: 2.132.0)

Code Analysis

Commit: 5e46913

Fix sensitive header leakage by implementing origin-based header scoping and manual redirect verification.

Mitigation Strategies

  • Upgrade docling and docling-slim dependencies to version 2.132.0 or higher.
  • Configure explicit allowed origins using headers_allowed_origins in backend options.
  • Disable remote resource fetching (enable_remote_fetch=False) when handling untrusted documents.

Remediation Steps:

  1. Identify all service deployments utilizing docling and docling-slim.
  2. Update requirements.txt, pyproject.toml, or poetry configurations to request docling>=2.132.0.
  3. Locate HTMLBackendOptions initializations and supply explicit hosts within the headers_allowed_origins configuration parameter.
  4. Redeploy services and monitor logs for warning messages indicating unauthorized origin attempts.

References


Read the full report for CVE-2026-105742 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)