4.3

CVE-2026-105747

Docling: METS-GBS archive member limit enforced after full member enumeration (memory exhaustion during format detection)

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.131.0, METS-GBS format detection in docling/datamodel/document.py and the backend in docling/backend/mets_gbs_backend.py call tarfile.TarFile.getmembers() before enforcing the max_member_count limit, causing the full archive member list to be allocated before the limit can stop processing. A small gzip-compressed tar archive with a very large number of empty members can therefore consume memory proportional to the declared member count, including during format detection before the allowed_formats restriction is applied. This issue is a residual weakness in the member-count protection added for CVE-2026-44018. This issue is fixed in 2.131.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Docling ≫ Docling Version >= 2.45.0 < 2.131.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.23% 0.131
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
CWE-409 Improper Handling of Highly Compressed Data (Data Amplification)

The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.

CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

https://github.com/docling-project/docling/releases/tag/v2.131.0
Release Notes
https://github.com/docling-project/docling/security/advisories/GHSA-3cr3-8m4c-fpxw
Patch
Vendor Advisory
https://github.com/docling-project/docling/pull/4412
Patch
Issue Tracking
https://github.com/docling-project/docling/commit/ebae65cd71c37c88b36185b406a449b92d8f7ffa
Patch