{"id":"CVE-2026-105745","summary":"Docling: Plugin entry points are imported before the allow_external_plugins check","details":"Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.27.0 until 2.131.0, Docling plugin factories in docling/models/factories/base_factory.py call load_setuptools_entrypoints() before applying the allow_external_plugins setting, so every module registered in the Docling entry-point group is imported even when external plugins are disabled. An installed third-party or compromised package can therefore execute import-time code when Docling starts, while the subsequent namespace filter misleadingly reports that the plugin was not loaded. This issue is fixed in 2.131.0.","aliases":["GHSA-9jxx-vjrv-h2rq"],"modified":"2026-10-07T02:47:27.650949146Z","published":"2026-10-05T21:29:23.561Z","database_specific":{"cwe_ids":["CWE-696","CWE-829"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105745.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/docling-project/docling/releases/tag/v2.131.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105745.json"},{"type":"ADVISORY","url":"https://github.com/docling-project/docling/security/advisories/GHSA-9jxx-vjrv-h2rq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105745"},{"type":"FIX","url":"https://github.com/docling-project/docling/commit/0f443b3786e98688a2da3b7c8f56fe5e46af876c"},{"type":"FIX","url":"https://github.com/docling-project/docling/pull/4413"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/docling-project/docling","events":[{"introduced":"1a2a9e4eff9be804dfaed25fb4796afe66be6f60"},{"fixed":"0f443b3786e98688a2da3b7c8f56fe5e46af876c"},{"fixed":"cb14c87372f3379de9ac19fa46aacf6abc762119"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"2.27.0"},{"fixed":"2.131.0"}]}}],"versions":["v2.130.0","v2.129.0","v2.128.0","v2.127.0","v2.126.0","v2.125.0","v2.124.0","v2.123.1","v2.123.0","v2.122.0","v2.121.0","v2.120.3","v2.120.2","v2.120.1","v2.120.0","v2.119.0","v2.118.1","v2.118.0","v2.117.0","v2.116.0","v2.115.0","v2.114.0","v2.113.0","v2.112.0","v2.111.0","v2.110.0","v2.109.0","v2.108.0","v2.107.0","v2.106.0","v2.105.0","v2.104.0","v2.103.0","v2.102.2","v2.102.1","v2.102.0","v2.101.0","v2.100.0","v2.99.0","v2.98.0","v2.97.0","v2.96.1","v2.96.0","v2.95.0","v2.94.0","v2.93.0","v2.92.0","v2.90.1","v2.91.0","v2.90.0","v2.89.0","v2.88.0","v2.87.0","v2.86.0","v2.85.0","v2.84.0","v2.83.0","v2.82.0","v2.81.0","v2.80.0","v2.79.0","v2.78.0","v2.77.0","v2.76.0","v2.75.0","v2.74.0","v2.73.1","v2.73.0","v2.72.0","v2.71.0","v2.70.0","v2.69.1","v2.69.0","v2.68.0","v2.67.0","v2.66.0","v2.65.0","v2.64.1","v2.64.0","v2.63.0","v2.62.0","v2.61.2","v2.61.1","v2.61.0","v2.60.1","v2.60.0","v2.59.0","v2.58.0","v2.57.0","v2.56.1","v2.56.0","v2.55.1","v2.55.0","v2.54.0","v2.53.0","v2.52.0","v2.51.0","v2.50.0","v2.49.0","v2.48.0","v2.47.1","v2.47.0","v2.46.0","v2.45.0","v2.44.0","v2.43.0","v2.42.2","v2.42.1","v2.42.0","v2.41.0","v2.40.0","v2.39.0","v2.38.1","v2.38.0","v2.37.0","v2.36.1","v2.36.0","v2.35.0","v2.34.0","v2.33.0","v2.32.0","v2.31.2","v2.31.1","v2.31.0","v2.30.0","v2.29.0","v2.28.4","v2.28.3","v2.28.2","v2.28.1","v2.28.0","v2.27.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105745.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"}]}