CVE-2026-44018
EUVD-2026-3979026.06.2026, 16:16
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend's XML parsing and the input document format detection lacked security controls. An attacker could craft malicious METS-GBS archives that, when processed, could read sensitive files, exhaust system resources, or cause application crashes. This vulnerability is fixed in 2.91.0.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| docling | docling | 2.45.0 ≤ 𝑥 < 2.91.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration