Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend's XML parsing and the input document format detection lacked security controls. An attacker could craft malicious METS-GBS archives that, when processed, could read sensitive files, exhaust system resources, or cause application crashes. This vulnerability is fixed in 2.91.0.

Project Subscriptions

Vendors Products
Docling Subscribe
Docling Subscribe
Docling-project Subscribe
Docling Subscribe
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-r3xg-rg9j-67fv Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 02 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 26 Jun 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Docling-project
Docling-project docling
Vendors & Products Docling-project
Docling-project docling

Fri, 26 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 26 Jun 2026 16:00:00 +0000

Type Values Removed Values Added
Description Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend's XML parsing and the input document format detection lacked security controls. An attacker could craft malicious METS-GBS archives that, when processed, could read sensitive files, exhaust system resources, or cause application crashes. This vulnerability is fixed in 2.91.0.
Title Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend
Weaknesses CWE-409
CWE-611
CWE-776
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-06-26T19:13:39.619Z

Reserved: 2026-05-04T21:24:36.506Z

Link: CVE-2026-44018

cve-icon Vulnrichment

Updated: 2026-06-26T19:10:35.512Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-26T16:16:30.767

Modified: 2026-06-27T20:25:28.273

Link: CVE-2026-44018

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-06-26T15:40:42Z

Links: CVE-2026-44018 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-06-26T22:45:05Z

Weaknesses