Impact
The vulnerability causes infinite memory growth during the processing of a METS-GBS document. The system enumerates all members of a gzip‐compressed tar archive before checking the maximum member count, allocating memory proportional to the declared member count while still in format detection mode. An attacker can craft a very large, seemingly empty archive that, once loaded, exhausts available memory and potentially brings the process or host down. This flaw falls under the CWE-409 and CWE-770 categories.
Affected Systems
The affected products are docling-project’s docling and docling-slim modules. Versions from 2.45.0 through 2.130.x contain the flaw. Up-to-date releases starting with 2.131.0 have a patch that prevents the excessive allocation by enforcing the member limit prior to enumeration.
Risk and Exploitability
With a CVSS score of 4.3 the flaw is considered low severity. The EPSS score is not available and the CVE is not listed in CISA KEV, indicating a limited awareness of active exploitation. The primary attack vector requires the ability to feed a crafted archive to the system, so an internal user or a compromised process could trigger it. The impact is a denial of service through memory exhaustion, but there is no evidence of remote code execution or data disclosure.
OpenCVE Enrichment