| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-q43m-vhcp-mhvm | Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 06 Oct 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Docling-project
Docling-project docling |
|
| Vendors & Products |
Docling-project
Docling-project docling |
Tue, 06 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 05 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.82.0 until 2.118.1, HTMLBackendOptions(render_page=True) permits file URLs because HTMLDocumentBackend._get_browser_request_block_reason does not enforce the enable_local_fetch setting or confine local requests to the source document directory. Crafted path-backed HTML can embed a readable local text file in a browser-rendered page image when Playwright is installed. Only filesystem Path inputs are affected because stream inputs use an opaque origin, and the default configuration, command-line interface, docling-serve, and non-rendering backends are not affected. This issue is fixed in 2.118.1. | |
| Title | Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode | |
| Weaknesses | CWE-552 CWE-863 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-06T18:17:27.884Z
Reserved: 2026-10-05T19:11:07.947Z
Link: CVE-2026-105750
Updated: 2026-10-06T18:17:24.317Z
Status : Undergoing Analysis
Published: 2026-10-05T22:16:58.097
Modified: 2026-10-06T19:17:41.540
Link: CVE-2026-105750
OpenCVE Enrichment
Updated: 2026-10-06T20:45:05Z
Github GHSA