Description
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.131.0, METS-GBS format detection in docling/datamodel/document.py and the backend in docling/backend/mets_gbs_backend.py call tarfile.TarFile.getmembers() before enforcing the max_member_count limit, causing the full archive member list to be allocated before the limit can stop processing. A small gzip-compressed tar archive with a very large number of empty members can therefore consume memory proportional to the declared member count, including during format detection before the allowed_formats restriction is applied. This issue is a residual weakness in the member-count protection added for CVE-2026-44018. This issue is fixed in 2.131.0.
Published: 2026-10-05
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Memory Exhaustion
Action: Apply Patch
AI Analysis

Impact

The vulnerability causes infinite memory growth during the processing of a METS-GBS document. The system enumerates all members of a gzip‐compressed tar archive before checking the maximum member count, allocating memory proportional to the declared member count while still in format detection mode. An attacker can craft a very large, seemingly empty archive that, once loaded, exhausts available memory and potentially brings the process or host down. This flaw falls under the CWE-409 and CWE-770 categories.

Affected Systems

The affected products are docling-project’s docling and docling-slim modules. Versions from 2.45.0 through 2.130.x contain the flaw. Up-to-date releases starting with 2.131.0 have a patch that prevents the excessive allocation by enforcing the member limit prior to enumeration.

Risk and Exploitability

With a CVSS score of 4.3 the flaw is considered low severity. The EPSS score is not available and the CVE is not listed in CISA KEV, indicating a limited awareness of active exploitation. The primary attack vector requires the ability to feed a crafted archive to the system, so an internal user or a compromised process could trigger it. The impact is a denial of service through memory exhaustion, but there is no evidence of remote code execution or data disclosure.

Generated by OpenCVE AI on October 5, 2026 at 22:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade docling to version 2.131.0 or later.
  • If upgrading is not immediately possible, configure the application or environment to reject archives that exceed a safe member count or size before they reach docling.
  • Consider running docling in a resource‑restricted container or setting limits such as ulimit or cgroups to constrain memory usage during processing.

Generated by OpenCVE AI on October 5, 2026 at 22:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Docling-project
Docling-project docling
Vendors & Products Docling-project
Docling-project docling

Mon, 05 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Description Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.131.0, METS-GBS format detection in docling/datamodel/document.py and the backend in docling/backend/mets_gbs_backend.py call tarfile.TarFile.getmembers() before enforcing the max_member_count limit, causing the full archive member list to be allocated before the limit can stop processing. A small gzip-compressed tar archive with a very large number of empty members can therefore consume memory proportional to the declared member count, including during format detection before the allowed_formats restriction is applied. This issue is a residual weakness in the member-count protection added for CVE-2026-44018. This issue is fixed in 2.131.0.
Title Docling: METS-GBS archive member limit enforced after full member enumeration (memory exhaustion during format detection)
Weaknesses CWE-409
CWE-770
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'}


Subscriptions

Docling-project Docling
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T21:32:34.438Z

Reserved: 2026-10-05T19:11:07.947Z

Link: CVE-2026-105747

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T22:16:57.633

Modified: 2026-10-05T22:16:57.633

Link: CVE-2026-105747

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T22:30:19Z

Weaknesses
  • CWE-409

    Improper Handling of Highly Compressed Data (Data Amplification)

  • CWE-770

    Allocation of Resources Without Limits or Throttling