Executive brief
Docling, a tool used to convert and process documents for AI applications, contains a vulnerability in how it handles HTML files. An attacker could provide a specially crafted document that tricks the system into accessing private local files or internal network resources. This could lead to the exposure of sensitive data or cause the system to slow down by consuming excessive resources.
Technical details
The Docling HTML backend fails to properly validate resource URIs and file paths during document processing. Specifically, the library allowed 'file://' URIs and path traversal sequences (../), enabling unauthorized access to the local file system when 'enable_local_fetch' was active. Additionally, the backend lacked validation for internal network resources and HTTP redirects, creating a Server-Side Request Forgery (SSRF) risk. The vulnerability also includes a lack of resource limits for remote image downloads and data URIs, which can lead to uncontrolled resource consumption. These issues are addressed in version 2.94.0 by implementing IP validation, redirect checks, size limits, and stricter path containment.
Affected products
- docling-project docling < 2.94.0
Timeline
- 2026-06-02: advisory: GitHub security advisory published
- 2026-05-18: patched: Version 2.94.0 released
- 2026-06-26: disclosed: CVE published to NVD