PT-2026-46127 · Docling · Docling
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Docling versions prior to 2.94.0
Description
The HTML backend fails to perform sufficient validation during resource handling. This allows local file system access via
file:// URIs when enable local fetch is set to True, and enables path traversal outside intended directories through absolute paths or ../ sequences. Additionally, the system does not block internal network resources when enable remote fetch is True, fails to validate HTTP redirects, and lacks resource limits for data: URIs and remote image downloads. These issues can lead to Server-Side Request Forgery (SSRF), where an attacker induces the server to make requests to an internal or unintended resource.Recommendations
Update to version 2.94.0.
As a temporary workaround, keep both
enable local fetch and enable remote fetch set to False when processing untrusted HTML documents.Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Docling