PT-2026-46120 · Docling · Docling

·

CVE-2026-44018

·

Published

2026-06-03

·

Updated

2026-06-27

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Docling versions 2.45.0 through 2.90.0
Description The METS-GBS backend's XML parsing and input document format detection lack security controls. This allows for XML External Entity (XXE) attacks, which occur when an XML parser improperly handles external entity references, potentially allowing the reading of local files or causing a denial of service. Additionally, the system is susceptible to decompression bombs (zip bombs), where small archives expand to massive sizes, and unbounded archive extraction, both of which can exhaust memory and disk space or cause application crashes.
Recommendations Update to version 2.91.0. Avoid processing METS-GBS archives from untrusted sources. Pre-validate archives in an isolated environment with resource limits.

Exploit

Fix

XXE

XML Entity Expansion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44018
GHSA-R3XG-RG9J-67FV
PYSEC-2026-2144

Affected Products

Docling