CVE-2026-105742

Source
https://cve.org/CVERecord?id=CVE-2026-105742
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105742.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-105742
Aliases
Published
2026-10-05T21:21:43Z
Modified
2026-10-07T02:47:27Z
Severity
  • 3.7 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Docling: Configured HTTP headers sent to every remote image host named by a document
Details

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.95.0 until 2.132.0, the HTML image resource loader in docling/backend/utils/image_resource_loader.py forwards headers configured through the HTMLBackendOptions.headers setting to every remote image URL named by an untrusted document when enable_remote_fetch=True and fetch_images=True. The loader does not restrict those credentials to the source document's origin, allowing requests that carry custom headers such as API keys and cookies to follow cross-origin redirects and expose the caller's configured credentials to a document author. The default configuration is not affected because remote fetching and configured headers are required. This issue is fixed in 2.132.0.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-201",
        "CWE-522"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105742.json"
}
References

Affected packages

Git / github.com/docling-project/docling

Affected ranges

Type
GIT
Repo
https://github.com/docling-project/docling
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2.95.0"
        },
        {
            "fixed": "2.132.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v2.*
v2.100.0
v2.101.0
v2.102.0
v2.102.1
v2.102.2
v2.103.0
v2.104.0
v2.105.0
v2.106.0
v2.107.0
v2.108.0
v2.109.0
v2.110.0
v2.111.0
v2.112.0
v2.113.0
v2.114.0
v2.115.0
v2.116.0
v2.117.0
v2.118.0
v2.118.1
v2.119.0
v2.120.0
v2.120.1
v2.120.2
v2.120.3
v2.121.0
v2.122.0
v2.123.0
v2.123.1
v2.124.0
v2.125.0
v2.126.0
v2.127.0
v2.128.0
v2.129.0
v2.130.0
v2.131.0
v2.95.0
v2.96.0
v2.96.1
v2.97.0
v2.98.0
v2.99.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105742.json"