Exposure of Resource to Wrong Sphere Affecting docling-slim package, versions [2.92.0, 2.131.0)


Severity

Recommended
0.0
low
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.22% (12th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-DOCLINGSLIM-20537063
  • published6 Oct 2026
  • disclosed5 Oct 2026
  • creditJeff Witt

Introduced: 5 Oct 2026

NewCVE-2026-105746  (opens in a new tab)
CWE-668  (opens in a new tab)

How to fix?

Upgrade docling-slim to version 2.131.0 or higher.

Overview

docling-slim is a Modular version of the Docling package: SDK and CLI for parsing PDF, DOCX, HTML, and more, to a unified document representation for powering downstream workflows such as gen AI applications.

Affected versions of this package are vulnerable to Exposure of Resource to Wrong Sphere via the KserveV2OcrModel class in docling/models/stages/ocr/kserve_v2_ocr_model.py, which contacts a remote KServe v2 inference server without checking the enable_remote_services flag. Unlike all other remote engines in the pipeline, this engine unconditionally establishes an outbound connection to the configured inference server, bypassing the authorization gate that is meant to require explicit user opt-in before any remote service contact occurs. An attacker or misconfigured deployment can cause the application to exfiltrate page-crop image data to an unintended remote endpoint.

Note: This is only exploitable when the KServe v2 OCR engine (KserveV2OcrOptions) is selected as the OCR backend.

CVSS Base Scores

version 4.0
version 3.1