Disclosure summary
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.82.0 until 2.118.1, HTMLBackendOptions(render_page=True) permits file URLs because HTMLDocumentBackend._get_browser_request_block_reason does not enforce the enable_local_fetch setting or confine local requests to the source document directory. Crafted path-backed HTML can embed a readable local text file in a browser-rendered page image when Playwright is installed. Only filesystem Path inputs are affected because stream inputs use an opaque origin, and the default configuration, command-line interface, docling-serve, and non-rendering backends are not affected. This issue is fixed in 2.118.1.
Source-reported weakness categories
CWE-552, CWE-863
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-105750
Open original source · Updated Oct 06, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
GitHub Reviewed Security Advisories · GHSA-q43m-vhcp-mhvm
Open original source · Updated Oct 05, 2026
Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode
Source severity: MEDIUM / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | docling | >= 2.82.0, < 2.118.1 | 2.118.1 |
| pip | docling-slim | >= 2.92.0, < 2.118.1 | 2.118.1 |
Original records & references
PUBLISHED 2026-10-05T18:16:58-04:00
MODIFIED 2026-10-06T10:59:48-04:00
INGESTED 2026-10-06T11:45:40-04:00