CVE-2026-105750: Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode
### Summary When the HTML backend renders pages in a headless browser (`HTMLBackendOptions(render_page=True)`), the `enable_local_fetch` option is not enforced. A crafted HTML file can embed an arbitrary local file...