PT-2026-39633 · Docling · Docling

Published

2026-05-11

·

Updated

2026-05-11

·

CVE-2026-31248

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Docling versions prior to 2.61.1
Description The METS GBS backend is susceptible to XML Entity Expansion (XXE) attacks. The system extracts and validates XML files from .tar.gz archives using the etree.fromstring() function without disabling entity resolution. A remote attacker can provide a malicious XML file containing nested entity definitions, known as an XML Bomb, within a .tar.gz archive. This causes exponential expansion of entities during parsing, leading to excessive resource consumption and a denial of service (DoS) condition.
Recommendations Update to a version later than 2.61.0.

Fix

XML Entity Expansion

Weakness Enumeration

Related Identifiers

CVE-2026-31248
GHSA-9F4Q-Q82Q-4359

Affected Products

Docling