PULSE
FEED
ransompanzer reclama a SweetRush · US · Professional Servicesransomincransom reclama a magnals.com · US · Otherransomdeadlock reclama a Greggio Argento · IT · Agriculture and Food Productionransomeverest reclama a Agri Industrial · Agriculture and Food Productionransomeverest reclama a B-accountants · NL · Professional Servicesransomeverest reclama a Morcon Developments · Otherransomeverest reclama a Kennametal · US · Manufacturingransomeverest reclama a Flydubai · AE · Transportationransomumbra reclama a Four Hands LLC · US · Otherransomakira reclama a Michael K Shelby, CPA · Professional Servicesransomakira reclama a Hygrade · US · Agriculture and Food Productionransomqilin reclama a CORBY ROCK MILL · IE · Manufacturingransomqilin reclama a Delta Marine · FI · Transportationransomqilin reclama a J&D Financial · Financial Servicesransompanzer reclama a SweetRush · US · Professional Servicesransomincransom reclama a magnals.com · US · Otherransomdeadlock reclama a Greggio Argento · IT · Agriculture and Food Productionransomeverest reclama a Agri Industrial · Agriculture and Food Productionransomeverest reclama a B-accountants · NL · Professional Servicesransomeverest reclama a Morcon Developments · Otherransomeverest reclama a Kennametal · US · Manufacturingransomeverest reclama a Flydubai · AE · Transportationransomumbra reclama a Four Hands LLC · US · Otherransomakira reclama a Michael K Shelby, CPA · Professional Servicesransomakira reclama a Hygrade · US · Agriculture and Food Productionransomqilin reclama a CORBY ROCK MILL · IE · Manufacturingransomqilin reclama a Delta Marine · FI · Transportationransomqilin reclama a J&D Financial · Financial Services
← Todos los CVEs
CVE Watch6 oct 2026

CVE-2026-105748

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.16.0 u

CVSS

4.3

Medio

EPSS

—

KEV

—

Exploit Today

0

0-100

Publicado: 5 oct 2026 · Última mod.: 6 oct 2026 · CWE-73 · CWE-200

EPSS · 30d

Sin historial EPSS suficiente todavía.

Descripción técnica

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.16.0 until 2.131.0, the InputFormat.JSON_DOCLING backend in docling/backend/json/docling_json_backend.py validates serialized DoclingDocument input without rejecting picture image references that contain local paths or file URIs. When the document is enriched or exported with ImageRefMode.EMBEDDED, the DoclingDocument._with_embedded_pictures and ImageRef.pil_image methods can open those references and place readable image bytes in Markdown or HTML output. Disclosure is limited to files Pillow can decode as images, while differing decode behavior can also reveal whether a path exists. Direct untrusted loading through docling-core is outside this Docling fix. This issue is fixed in 2.131.0.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-106424—
—
———Information leak in Audio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)2h
CVE-2026-106415—
—
———Information leak in Enterprise in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)2h
CVE-2026-106392—
—
———Information leak in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)2h
CVE-2026-106360—
—
———Information leak in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)2h
CVE-2026-106348—
—
———Information leak in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)2h
CVE-2026-106342—
—
———Information leak in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)2h