Docling, SSRF Guard Bypass, CVE-2026-105743 (Medium) -DC-Oct2026-2863

Listen to this Post

DailyCVE Form:

Platform: Docling
Version: Before 2.132.0
Vulnerability: SSRF Guard Bypass
Severity: Medium
date: October 2026

Prediction: Already patched version

The vulnerability CVE-2026-105743 affects Docling versions from 2.91.0 up to 2.132.0.
It resides in the URL safety validation mechanism used across multiple backends.
When remote fetching features are enabled, docling attempts to block local requests.
However, its IP validation logic can be completely bypassed by attackers.
The security check resolves the hostname once via socket.gethostbyname().
This returns a single IPv4 address which is then validated against internal filters.
Following this validation, the original URL string is passed directly to requests.
The underlying urllib3 client then performs an independent DNS resolution.
This second lookup can return different answers via DNS rebinding attacks.
It can also exploit mixed public A records and internal AAAA records.
Furthermore, parser discrepancies introduce a critical weakness in the design.
Python’s urllib.parse treats a backslash in the authority section as part of the host.
Meanwhile, urllib3 ends the authority section immediately at the backslash character.
An attacker can craft a malicious URL containing a backslash symbol.
An example of this payload format is http://127.0.0.1:8080@1.1.1.1/x.png.
In this case, the safety check validates the public IP address 1.1.1.1.
However, the HTTP client connects directly to the internal address 127.0.0.1.
Additionally, in HTML browser-rendering mode where render_page equals true,
all inbound and outbound requests made by the page are fully permitted.
These requests are allowed for any HTTP or HTTPS URL without any IP check.
Although JavaScript execution is disabled during this rendering process,
the browser path can still expose internal responses passively in screenshots.
This flaw allows unauthorized access to sensitive internal services.
Such internal services include cloud metadata endpoints and local loopback apps.
Attackers leverage these weaknesses to read unintended internal resources.
The vulnerability requires remote fetching configurations to be explicitly enabled.
It is resolved in version 2.132.0 by updating validation and host parsing logic.

What Undercode Say

Check installed docling version
pip show docling
Run conversion with remote fetch configuration
python -c "
from docling.document_converter import DocumentConverter, PdfFormatOption
from docling.datamodel.pipeline_options import PdfPipelineOptions
pipeline_options = PdfPipelineOptions()
pipeline_options.enable_remote_fetch = True
converter = DocumentConverter()
"

Exploit: (Educational Purposes!)

Malicious URL leveraging backslash parser discrepancy
exploit_url = "http://127.0.0.1:8080\@1.1.1.1/x.png"
The validate_url_safety function checks 1.1.1.1 while urllib3 connects to 127.0.0.1:8080

Protection: from this CVE

Upgrade to docling version 2.132.0 or higher.

Keep `enable_remote_fetch=False` for untrusted documents.

Block egress to private, link-local, and loopback ranges at the network level.

Impact:

Requests from the converting host to internal services such as cloud metadata endpoints and loopback services. Response content is exposed only when it decodes as an image or is rendered into the page screenshot.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top