CVE-2026-105743: CVE-2026-105743: Server-Side Request Forgery Guard Bypass in Docling Document Conversion Engine
CVE-2026-105743: Server-Side Request Forgery Guard Bypass in Docling Document Conversion Engine Vulnerability ID: CVE-2026-105743 CVSS Score: 4.0 Published: 2026-10-07 An SSRF guard bypass vulnerability in the Docli
CVE-2026-105743: Server-Side Request Forgery Guard Bypass in Docling Document Conversion Engine
Vulnerability ID: CVE-2026-105743
CVSS Score: 4.0
Published: 2026-10-07
An SSRF guard bypass vulnerability in the Docling document conversion engine allows unauthenticated attackers to bypass internal IP access controls. The vulnerability exists due to a DNS rebinding Time-of-Check Time-of-Use (TOCTOU) condition, URL authority parsing inconsistencies, and unvalidated network requests triggered during headless browser page rendering.
TL;DR
Unauthenticated Server-Side Request Forgery (SSRF) bypass in Docling via DNS Rebinding, URL parsing inconsistencies, and Playwright subresource fetching, allowing internal resource scanning and AWS metadata exfiltration.
β οΈ Exploit Status: POC
Technical Details
- Vulnerability ID: CVE-2026-105743
- CWE ID: CWE-918 (Server-Side Request Forgery), CWE-367 (TOCTOU)
- CVSS Base Score: 4.0 (Medium)
- Attack Vector: Network (AV:N)
- Attack Complexity: High (AC:H)
- Exploit Status: Proof of Concept (PoC)
- CISA KEV Status: Not Listed
Affected Systems
- docling
- docling-slim
-
docling: >= 2.91.0, < 2.132.0 (Fixed in:
2.132.0) -
docling-slim: >= 2.91.0, < 2.132.0 (Fixed in:
2.132.0)
Code Analysis
Commit: 5e46913
Fix DNS rebinding SSRF and Playwright browser bypass in resource loading logic
Exploit Details
- GitHub Security Advisory: GHSA security advisory detail outlining the SSRF bypass and Playwright isolation fixes.
Mitigation Strategies
- Upgrade Docling dependency to version 2.132.0 or higher.
- Disable remote resource fetching if external page resources do not require parsing.
- Isolate the application's network access using runtime container firewalls or network security groups.
Remediation Steps:
- Step 1: Execute the dependency upgrade command:
pip install --upgrade docling docling-slim. - Step 2: Validate the upgrade within the local Python runtime environment:
python -c "import docling; print(docling.__version__)"(Verify version >= 2.132.0). - Step 3: Modify backend instantiation configurations to keep
enable_remote_fetch=Falseunless specifically required. - Step 4: Block outbound connections to local networks and cloud metadata ranges (such as
169.254.169.254) by applying network isolation policies (e.g., using iptables, Kubernetes NetworkPolicies, or AWS Security Groups).
References
- Docling Security Advisory - GHSA-pc36-qwjq-x68c
- Official Patch Commit
- Official Pull Request #4420
- Release Notes Tag v2.132.0
- National Vulnerability Database Link
Read the full report for CVE-2026-105743 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.