PatchSiren cyber security CVE debrief
CVE-2026-105746 docling-project CVE debrief
CVE-2026-105746: Docling remote OCR processing issue. The vulnerability exists in Docling versions from 2.83.0 until 2.131.0 due to the KServeV2OcrModel class and StandardPdfPipeline._make_ocr_model method not properly checking the pipeline_options.enable_remote_services setting, allowing remote OCR processing even when configured to be disabled. This issue may lead to unintended data exposure in configurations that rely on remote services being disabled. Roles responsible for configuring and maintaining Docling installations should assess exposure and verify configurations.
- Vendor
- docling-project
- Product
- docling
- CVSS
- LOW 2.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-05
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-05
- Advisory updated
- 2026-10-08
Who should care
Roles responsible for configuring and maintaining Docling installations, especially those relying on remote services being disabled, should assess exposure and verify configurations.
Why it matters
CVE-2026-105746 allows remote OCR processing in Docling configurations that rely on remote services being disabled, potentially leading to unintended data exposure. Roles responsible for configuring and maintaining Docling installations should assess exposure and verify configurations.
- Remote OCR processing may occur even when configured to be disabled, potentially leading to unintended data exposure.
- Configurations relying on remote services being disabled may be vulnerable to this issue.
- Verification of inventory and configurations is necessary to ensure proper mitigation.
Technical summary
The KServeV2OcrModel class in docling/models/stages/ocr/kserve_v2_ocr_model.py and the StandardPdfPipeline._make_ocr_model method do not properly check the pipeline_options.enable_remote_services setting, allowing remote OCR processing even when configured to be disabled. This issue exists in Docling versions from 2.83.0 until 2.131.0. The destination for remote OCR processing is configured by the caller rather than selected by an attacker. To address this issue, users should update to version 2.131.0 or later and verify configurations to ensure remote services are properly disabled.
Defensive priority
Assess exposure in Docling configurations relying on remote services being disabled; verify inventory and configurations.
Recommended defensive actions
- Assess Docling configurations for exposure to remote OCR processing
- Verify inventory and configurations to ensure remote services are properly disabled
- Update to version 2.131.0 or later
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The issue exists in Docling versions from 2.83.0 until 2.131.0 due to the KServeV2OcrModel class and StandardPdfPipeline._make_ocr_model method not properly checking the pipeline_options.enable_remote_services setting.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105746 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105746
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105746 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105746
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
PYSEC-2026-4193
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/PyPI/PYSEC-2026-4193.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/docling-project/docling/releases/tag/v2.131.0
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/docling-project/docling/commit/7d6d0c4810dff4885017c53890be6dc5a22ca68b
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/docling-project/docling/pull/4418
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/docling-project/docling/security/advisories/GHSA-h42j-9hcc-3cwc
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.