{"id":"PYSEC-2026-4192","details":"Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.27.0 until 2.131.0, Docling plugin factories in docling/models/factories/base_factory.py call load_setuptools_entrypoints() before applying the allow_external_plugins setting, so every module registered in the Docling entry-point group is imported even when external plugins are disabled. An installed third-party or compromised package can therefore execute import-time code when Docling starts, while the subsequent namespace filter misleadingly reports that the plugin was not loaded. This issue is fixed in 2.131.0.","aliases":["CVE-2026-105745","GHSA-9jxx-vjrv-h2rq"],"modified":"2026-10-08T10:00:02.907008754Z","published":"2026-10-05T22:16:57.330Z","references":[{"type":"ADVISORY","url":"https://github.com/docling-project/docling/releases/tag/v2.131.0"},{"type":"FIX","url":"https://github.com/docling-project/docling/commit/0f443b3786e98688a2da3b7c8f56fe5e46af876c"},{"type":"FIX","url":"https://github.com/docling-project/docling/pull/4413"},{"type":"FIX","url":"https://github.com/docling-project/docling/security/advisories/GHSA-9jxx-vjrv-h2rq"}],"affected":[{"package":{"name":"docling","ecosystem":"PyPI","purl":"pkg:pypi/docling"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.27.0"},{"fixed":"2.131.0"}]}],"versions":["2.100.0","2.101.0","2.102.0","2.102.1","2.102.2","2.103.0","2.104.0","2.105.0","2.106.0","2.107.0","2.108.0","2.109.0","2.110.0","2.111.0","2.112.0","2.113.0","2.114.0","2.115.0","2.116.0","2.117.0","2.118.0","2.118.1","2.119.0","2.120.1","2.120.2","2.120.3","2.121.0","2.122.0","2.123.0","2.123.1","2.124.0","2.125.0","2.126.0","2.127.0","2.128.0","2.129.0","2.130.0","2.27.0","2.28.0","2.28.1","2.28.2","2.28.3","2.28.4","2.29.0","2.30.0","2.31.0","2.31.1","2.31.2","2.32.0","2.33.0","2.34.0","2.35.0","2.36.0","2.36.1","2.37.0","2.38.0","2.38.1","2.39.0","2.40.0","2.41.0","2.42.0","2.42.1","2.42.2","2.43.0","2.44.0","2.45.0","2.46.0","2.47.0","2.47.1","2.48.0","2.49.0","2.50.0","2.51.0","2.52.0","2.53.0","2.54.0","2.55.0","2.55.1","2.56.0","2.56.1","2.57.0","2.58.0","2.59.0","2.60.0","2.60.1","2.61.0","2.61.1","2.61.2","2.62.0","2.63.0","2.64.0","2.64.1","2.65.0","2.66.0","2.67.0","2.68.0","2.69.0","2.69.1","2.70.0","2.71.0","2.72.0","2.73.0","2.73.1","2.74.0","2.75.0","2.76.0","2.77.0","2.78.0","2.79.0","2.80.0","2.81.0","2.82.0","2.83.0","2.84.0","2.85.0","2.86.0","2.87.0","2.88.0","2.89.0","2.90.0","2.91.0","2.92.0","2.93.0","2.94.0","2.95.0","2.96.0","2.96.1","2.97.0","2.98.0","2.99.0"],"ecosystem_specific":{},"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/docling/PYSEC-2026-4192.yaml"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}