{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-105745","assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","state":"PUBLISHED","assignerShortName":"GitHub_M","dateReserved":"2026-10-05T19:11:07.946Z","datePublished":"2026-10-05T21:29:23.561Z","dateUpdated":"2026-10-06T14:48:57.716Z"},"containers":{"cna":{"title":"Docling: Plugin entry points are imported before the allow_external_plugins check","problemTypes":[{"descriptions":[{"cweId":"CWE-696","lang":"en","description":"CWE-696: Incorrect Behavior Order","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-829","lang":"en","description":"CWE-829: Inclusion of Functionality from Untrusted Control Sphere","type":"CWE"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":6.7,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"name":"https://github.com/docling-project/docling/security/advisories/GHSA-9jxx-vjrv-h2rq","tags":["x_refsource_CONFIRM"],"url":"https://github.com/docling-project/docling/security/advisories/GHSA-9jxx-vjrv-h2rq"},{"name":"https://github.com/docling-project/docling/pull/4413","tags":["x_refsource_MISC"],"url":"https://github.com/docling-project/docling/pull/4413"},{"name":"https://github.com/docling-project/docling/commit/0f443b3786e98688a2da3b7c8f56fe5e46af876c","tags":["x_refsource_MISC"],"url":"https://github.com/docling-project/docling/commit/0f443b3786e98688a2da3b7c8f56fe5e46af876c"},{"name":"https://github.com/docling-project/docling/releases/tag/v2.131.0","tags":["x_refsource_MISC"],"url":"https://github.com/docling-project/docling/releases/tag/v2.131.0"}],"affected":[{"vendor":"docling-project","product":"docling","versions":[{"version":">= 2.27.0, < 2.131.0","status":"affected"}]},{"vendor":"docling-project","product":"docling-slim","versions":[{"version":">= 2.27.0, < 2.131.0","status":"affected"}]}],"providerMetadata":{"orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M","dateUpdated":"2026-10-05T21:29:23.561Z"},"descriptions":[{"lang":"en","value":"Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.27.0 until 2.131.0, Docling plugin factories in docling/models/factories/base_factory.py call load_setuptools_entrypoints() before applying the allow_external_plugins setting, so every module registered in the Docling entry-point group is imported even when external plugins are disabled. An installed third-party or compromised package can therefore execute import-time code when Docling starts, while the subsequent namespace filter misleadingly reports that the plugin was not loaded. This issue is fixed in 2.131.0."}],"source":{"advisory":"GHSA-9jxx-vjrv-h2rq","discovery":"UNKNOWN"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-10-06T14:35:59.694379Z","id":"CVE-2026-105745","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-10-06T14:48:57.716Z"}}]}}