Impact
docling-serve provides PDF and document services through an HTTP API. In releases 1.14.0 through 1.36.0 the endpoints /v1/memory/stats and /v1/memory/counts incorrectly omit the authentication guard, allowing anyone to request memory telemetry, object type histograms, and trigger repeated GC collection. This missing authentication (CWE‑306) exposes sensitive runtime information and can facilitate denial‑of‑service actions by overloading the memory collection routine.
Affected Systems
Vulnerable deployments are those running any docling-serve release from 1.14.0 up to 1.36.0 and exposing the memory endpoints to any network that can reach them. The issue exists in the open‑source project maintained by the docling‑project; no other vendor variants are listed.
Risk and Exploitability
The CVSS base score of 6.3 indicates moderate severity, affecting confidentiality and integrity when an attacker obtains the memory data. EPSS is not available, so precise exploitation probability is unknown, and the vulnerability is not included in CISA’s KEV catalog. An attacker can exploit the flaw over the network by issuing unauthenticated HTTP requests to the /v1/memory/stats and /v1/memory/counts endpoints, thereby bypassing the DOCLING_SERVE_API_KEY enforcement. This inference is based on the documented omission of the authentication dependency.
OpenCVE Enrichment