Docling (5 Oct CVE batch, CVE-2026-105742 to 105751): ten document-parser advisories, top CVSS 7.5 for file read/write via opt-in Tectonic TikZ rendering, plus local file reads and SSRF guard bypass — upgrade to 2.132.0
Ten CVE records for Docling, the open-source document conversion library widely used to feed PDFs and office files into RAG and other generative AI pipelines, were published on 5 October 2026 from its GitHub advisories. The most serious, CVE-2026-105744 (GHSA-x3q2-h9hx-4r4j, CVSS 3.1 7.5), affects callers that opt into the Tectonic engine for TikZ in LaTeX input (2.94.0 to before 2.132.0): crafted input can read files the converter can access and create or overwrite writable files, and turning on the shell-escape option also allows shell commands; the default configuration is not affected. CVE-2026-105751 (GHSA-4xhp-xg4w-8ppm, CVSS 4.0 6.9) lets an OpenDocument file's draw:image reference read local files that decode as images into the converted output (2.107.0 to before 2.120.3). Others cover an SSRF guard that can be bypassed with DNS rebinding or mixed address records when remote fetching is enabled (CVE-2026-105743), enable_local_fetch not enforced in HTML browser-rendering mode (CVE-2026-105750), plugin entry points imported before the allow_external_plugins check (CVE-2026-105745), configured HTTP headers sent to every remote image host (CVE-2026-105742), local images embedded via crafted DoclingDocument JSON (CVE-2026-105748), CPU or memory exhaustion from oversized tables or archives (CVE-2026-105747, CVE-2026-105749), and a KServe OCR remote-services setting not enforced (CVE-2026-105746). The advisories do not report exploitation. Primary: Docling GitHub security advisories.
- Product
- Docling and docling-slim (PyPI document conversion library for generative AI pipelines)
- Versions
- Fixed versions per advisory: 2.132.0 (CVE-2026-105742, 105743, 105744), 2.131.0 (105745 to 105749), 2.120.3 (105751), 2.118.1 (105750). Affected ranges start between 2.0.0 and 2.107.0 depending on the CVE. Upgrade to 2.132.0 or later covers all ten (current PyPI release is 2.133.0).
- CVSS
- highest (CVSS 3.1, CVE-2026-105744); CVE-2026-105751 6.9 (CVSS 4.0); others 2.2 to 6.7
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Upgrade docling and docling-slim to 2.132.0 or later. Treat every uploaded document as hostile: run conversion in a sandboxed container with no secrets mounted and no route to internal networks, leave Tectonic rendering, shell-escape, remote fetching and external plugins off unless you need them, and pin your plugin packages.
Primary: Docling GHSA-x3q2-h9hx-4r4j — file read/write via untrusted TikZ with opt-in Tectonic engine (CVE-2026-105744) · Vendor: Docling — GitHub security advisories index · CVE: CVE-2026-105742, CVE-2026-105744, CVE-2026-105751, CVE-2026-105743, CVE-2026-105750, CVE-2026-105745, CVE-2026-105748, CVE-2026-105747, CVE-2026-105749, CVE-2026-105746 · Docling GHSA-4xhp-xg4w-8ppm — local file read via draw:image in OpenDocument backend (CVE-2026-105751)
