PT-2026-46120 · Docling · Docling
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Docling versions 2.45.0 through 2.90.0
Description
The METS-GBS backend's XML parsing and input document format detection lack security controls. This allows for XML External Entity (XXE) attacks, which occur when an XML parser improperly handles external entity references, potentially allowing the reading of local files or causing a denial of service. Additionally, the system is susceptible to decompression bombs (zip bombs), where small archives expand to massive sizes, and unbounded archive extraction, both of which can exhaust memory and disk space or cause application crashes.
Recommendations
Update to version 2.91.0.
Avoid processing METS-GBS archives from untrusted sources.
Pre-validate archives in an isolated environment with resource limits.
Exploit
Fix
XXE
XML Entity Expansion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Docling