Bug 2546155 (CVE-2026-105743) - CVE-2026-105743 docling: docling: Server-Side Request Forgery via improper URL validation
Summary: CVE-2026-105743 docling: docling: Server-Side Request Forgery via improper UR...
Keywords:
Status: NEW
Alias: CVE-2026-105743
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-05 21:31 UTC by OSIDB Bzimport
Modified: 2026-10-05 21:42 UTC (History)
5 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-10-05 21:31:31 UTC
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.91.0 until 2.132.0, validate_url_safety in docling/backend/utils/image_resource_loader.py validates a hostname with a single IPv4 lookup and then allows the HTTP client to resolve and parse the original URL again, permitting DNS rebinding, mixed public and internal address records, and backslash authority parser disagreement to reach internal services. HTMLBackendOptions(render_page=True) also allows HTTP and HTTPS browser requests without validating their resolved destination. Exploitation requires remote fetching to be enabled, and response content is exposed only when it is decoded as an image or passively rendered in a page screenshot. This issue is fixed in 2.132.0.


Note You need to log in before you can comment on or make changes to this bug.