Impact
Docling versions 2.91.0 through 2.131.x validate a hostname with a single IPv4 lookup but then allow the HTTP client to resolve the original URL again. This introduces an SSRF guard bypass that can be used for DNS rebinding, mixed public and internal address records, and backslash authority parser disagreement. The vulnerability is only exploitable when remote fetching is enabled, and the retrieved content is exposed only when it is decoded as an image or passively rendered in a page screenshot. Based on the description, it is inferred that an attacker could craft a URL that resolves first to a public IP and then to an internal IP on the second lookup, causing the application to fetch internal resources that should be inaccessible.
Affected Systems
The docling-project product family, including docling and docling‑slim, is affected. Versions from 2.91.0 up to, but not including, 2.132.0 are vulnerable. The issue was fixed in version 2.132.0.
Risk and Exploitability
The CVSS score of 4 indicates low severity, and the EPSS score is not available. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the application to be configured with remote fetching enabled, and the attacker must control DNS resolution for a target URL. Based on the description, it is inferred that the attacker can manipulate DNS to cause the second lookup to resolve to an internal IP, enabling requests to internal services. The likely attack vector is remote via DNS rebinding, which could allow access to internal resources or further internal reconnaissance.
OpenCVE Enrichment