{"id":"PYSEC-2026-4189","details":"Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.95.0 until 2.132.0, the HTML image resource loader in docling/backend/utils/image_resource_loader.py forwards headers configured through the HTMLBackendOptions.headers setting to every remote image URL named by an untrusted document when enable_remote_fetch=True and fetch_images=True. The loader does not restrict those credentials to the source document's origin, allowing requests that carry custom headers such as API keys and cookies to follow cross-origin redirects and expose the caller's configured credentials to a document author. The default configuration is not affected because remote fetching and configured headers are required. This issue is fixed in 2.132.0.","aliases":["CVE-2026-105742","GHSA-p3fw-7699-7926"],"modified":"2026-10-08T10:00:02.905271868Z","published":"2026-10-05T22:16:56.867Z","references":[{"type":"ADVISORY","url":"https://github.com/docling-project/docling/releases/tag/v2.132.0"},{"type":"FIX","url":"https://github.com/docling-project/docling/commit/5e469137f275ffc443306a30d12a3a45bceb80fb"},{"type":"FIX","url":"https://github.com/docling-project/docling/pull/4420"},{"type":"FIX","url":"https://github.com/docling-project/docling/security/advisories/GHSA-p3fw-7699-7926"}],"affected":[{"package":{"name":"docling","ecosystem":"PyPI","purl":"pkg:pypi/docling"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.95.0"},{"fixed":"2.132.0"}]}],"versions":["2.100.0","2.101.0","2.102.0","2.102.1","2.102.2","2.103.0","2.104.0","2.105.0","2.106.0","2.107.0","2.108.0","2.109.0","2.110.0","2.111.0","2.112.0","2.113.0","2.114.0","2.115.0","2.116.0","2.117.0","2.118.0","2.118.1","2.119.0","2.120.1","2.120.2","2.120.3","2.121.0","2.122.0","2.123.0","2.123.1","2.124.0","2.125.0","2.126.0","2.127.0","2.128.0","2.129.0","2.130.0","2.131.0","2.95.0","2.96.0","2.96.1","2.97.0","2.98.0","2.99.0"],"ecosystem_specific":{},"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/docling/PYSEC-2026-4189.yaml"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}