PT-2026-39633 · Docling · Docling
Published
2026-05-11
·
Updated
2026-05-11
·
CVE-2026-31248
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Docling versions prior to 2.61.1
Description
The METS GBS backend is susceptible to XML Entity Expansion (XXE) attacks. The system extracts and validates XML files from .tar.gz archives using the
etree.fromstring() function without disabling entity resolution. A remote attacker can provide a malicious XML file containing nested entity definitions, known as an XML Bomb, within a .tar.gz archive. This causes exponential expansion of entities during parsing, leading to excessive resource consumption and a denial of service (DoS) condition.Recommendations
Update to a version later than 2.61.0.
Fix
XML Entity Expansion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Docling