PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105746 docling-project CVE debrief

CVE-2026-105746: Docling remote OCR processing issue. The vulnerability exists in Docling versions from 2.83.0 until 2.131.0 due to the KServeV2OcrModel class and StandardPdfPipeline._make_ocr_model method not properly checking the pipeline_options.enable_remote_services setting, allowing remote OCR processing even when configured to be disabled. This issue may lead to unintended data exposure in configurations that rely on remote services being disabled. Roles responsible for configuring and maintaining Docling installations should assess exposure and verify configurations.

Vendor
docling-project
Product
docling
CVSS
LOW 2.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-05
Original CVE updated
2026-10-08
Advisory published
2026-10-05
Advisory updated
2026-10-08

Who should care

Roles responsible for configuring and maintaining Docling installations, especially those relying on remote services being disabled, should assess exposure and verify configurations.

Why it matters

CVE-2026-105746 allows remote OCR processing in Docling configurations that rely on remote services being disabled, potentially leading to unintended data exposure. Roles responsible for configuring and maintaining Docling installations should assess exposure and verify configurations.

  • Remote OCR processing may occur even when configured to be disabled, potentially leading to unintended data exposure.
  • Configurations relying on remote services being disabled may be vulnerable to this issue.
  • Verification of inventory and configurations is necessary to ensure proper mitigation.

Technical summary

The KServeV2OcrModel class in docling/models/stages/ocr/kserve_v2_ocr_model.py and the StandardPdfPipeline._make_ocr_model method do not properly check the pipeline_options.enable_remote_services setting, allowing remote OCR processing even when configured to be disabled. This issue exists in Docling versions from 2.83.0 until 2.131.0. The destination for remote OCR processing is configured by the caller rather than selected by an attacker. To address this issue, users should update to version 2.131.0 or later and verify configurations to ensure remote services are properly disabled.

Defensive priority

Assess exposure in Docling configurations relying on remote services being disabled; verify inventory and configurations.

Recommended defensive actions

  • Assess Docling configurations for exposure to remote OCR processing
  • Verify inventory and configurations to ensure remote services are properly disabled
  • Update to version 2.131.0 or later
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The issue exists in Docling versions from 2.83.0 until 2.131.0 due to the KServeV2OcrModel class and StandardPdfPipeline._make_ocr_model method not properly checking the pipeline_options.enable_remote_services setting.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105746 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105746

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105746 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105746

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • PYSEC-2026-4193

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/PyPI/PYSEC-2026-4193.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/docling-project/docling/releases/tag/v2.131.0

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/docling-project/docling/commit/7d6d0c4810dff4885017c53890be6dc5a22ca68b

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/docling-project/docling/pull/4418

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/docling-project/docling/security/advisories/GHSA-h42j-9hcc-3cwc

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.