PULSE
FEED
ransompanzer reclama a SweetRush · US · Professional Servicesransomincransom reclama a magnals.com · US · Otherransomdeadlock reclama a Greggio Argento · IT · Agriculture and Food Productionransomeverest reclama a Agri Industrial · Agriculture and Food Productionransomeverest reclama a B-accountants · NL · Professional Servicesransomeverest reclama a Morcon Developments · Otherransomeverest reclama a Kennametal · US · Manufacturingransomeverest reclama a Flydubai · AE · Transportationransomumbra reclama a Four Hands LLC · US · Otherransomakira reclama a Michael K Shelby, CPA · Professional Servicesransomakira reclama a Hygrade · US · Agriculture and Food Productionransomqilin reclama a CORBY ROCK MILL · IE · Manufacturingransomqilin reclama a Delta Marine · FI · Transportationransomqilin reclama a J&D Financial · Financial Servicesransompanzer reclama a SweetRush · US · Professional Servicesransomincransom reclama a magnals.com · US · Otherransomdeadlock reclama a Greggio Argento · IT · Agriculture and Food Productionransomeverest reclama a Agri Industrial · Agriculture and Food Productionransomeverest reclama a B-accountants · NL · Professional Servicesransomeverest reclama a Morcon Developments · Otherransomeverest reclama a Kennametal · US · Manufacturingransomeverest reclama a Flydubai · AE · Transportationransomumbra reclama a Four Hands LLC · US · Otherransomakira reclama a Michael K Shelby, CPA · Professional Servicesransomakira reclama a Hygrade · US · Agriculture and Food Productionransomqilin reclama a CORBY ROCK MILL · IE · Manufacturingransomqilin reclama a Delta Marine · FI · Transportationransomqilin reclama a J&D Financial · Financial Services
← All CVEs
CVE WatchOct 6, 2026

CVE-2026-105748

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.16.0 u

CVSS

4.3

Medium

EPSS

—

KEV

—

Exploit Today

0

0-100

Published: Oct 5, 2026 · Last modified: Oct 6, 2026 · CWE-73 · CWE-200

EPSS · 30d

Not enough EPSS history yet.

Technical description

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.16.0 until 2.131.0, the InputFormat.JSON_DOCLING backend in docling/backend/json/docling_json_backend.py validates serialized DoclingDocument input without rejecting picture image references that contain local paths or file URIs. When the document is enriched or exported with ImageRefMode.EMBEDDED, the DoclingDocument._with_embedded_pictures and ImageRef.pil_image methods can open those references and place readable image bytes in Markdown or HTML output. Disclosure is limited to files Pillow can decode as images, while differing decode behavior can also reveal whether a path exists. Direct untrusted loading through docling-core is outside this Docling fix. This issue is fixed in 2.131.0.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-106424—
—
———Information leak in Audio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)3h
CVE-2026-106415—
—
———Information leak in Enterprise in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)3h
CVE-2026-106392—
—
———Information leak in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)3h
CVE-2026-106360—
—
———Information leak in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)3h
CVE-2026-106348—
—
———Information leak in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)3h
CVE-2026-106342—
—
———Information leak in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)3h