Impact
Docling includes an image loader that, when remote fetching is enabled, forwards HTTP headers specified in the backend options to every external image request. If an attacker supplies a document with remote image URLs, the loader will transmit custom headers—such as API keys or cookies—across domain boundaries, potentially exposing the caller's credentials to the document author. The weakness is a form of sensitive data exposure (CWE-201) and insufficiently protected credentials (CWE-522).
Affected Systems
The vulnerability affects the docling-project:docling and docling-project:docling-slim packages in versions from 2.95.0 up to and including 2.132.0. The default configuration is not impacted because both enable_remote_fetch and fetch_images must be true for the issue to manifest. The problem was addressed and fixed in release 2.132.0.
Risk and Exploitability
The assigned CVSS score of 3.7 classifies the flaw as low severity. No EPSS score is available, and the issue is not listed in CISA's KEV. Exploitation requires an untrusted document to trigger remote fetching with custom headers; if satisfied, the caller's credentials can be leaked to the document author. The fix in 2.132.0 removes this behavior.
OpenCVE Enrichment