{"id":"PYSEC-2026-4196","details":"Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.82.0 until 2.118.1, HTMLBackendOptions(render_page=True) permits file URLs because HTMLDocumentBackend._get_browser_request_block_reason does not enforce the enable_local_fetch setting or confine local requests to the source document directory. Crafted path-backed HTML can embed a readable local text file in a browser-rendered page image when Playwright is installed. Only filesystem Path inputs are affected because stream inputs use an opaque origin, and the default configuration, command-line interface, docling-serve, and non-rendering backends are not affected. This issue is fixed in 2.118.1.","aliases":["CVE-2026-105750","GHSA-q43m-vhcp-mhvm"],"modified":"2026-10-08T10:00:02.912153926Z","published":"2026-10-05T22:16:58.097Z","references":[{"type":"ADVISORY","url":"https://github.com/docling-project/docling/releases/tag/v2.118.1"},{"type":"FIX","url":"https://github.com/docling-project/docling/commit/1612b8875b0937447ce3122536fb5360a7102a0a"},{"type":"FIX","url":"https://github.com/docling-project/docling/pull/3948"},{"type":"FIX","url":"https://github.com/docling-project/docling/security/advisories/GHSA-q43m-vhcp-mhvm"}],"affected":[{"package":{"name":"docling","ecosystem":"PyPI","purl":"pkg:pypi/docling"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.82.0"},{"fixed":"2.118.1"}]}],"versions":["2.100.0","2.101.0","2.102.0","2.102.1","2.102.2","2.103.0","2.104.0","2.105.0","2.106.0","2.107.0","2.108.0","2.109.0","2.110.0","2.111.0","2.112.0","2.113.0","2.114.0","2.115.0","2.116.0","2.117.0","2.118.0","2.82.0","2.83.0","2.84.0","2.85.0","2.86.0","2.87.0","2.88.0","2.89.0","2.90.0","2.91.0","2.92.0","2.93.0","2.94.0","2.95.0","2.96.0","2.96.1","2.97.0","2.98.0","2.99.0"],"ecosystem_specific":{},"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/docling/PYSEC-2026-4196.yaml"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}