Description
docling-serve 1.14.0 through 1.36.0 contains a missing authentication vulnerability that allows unauthenticated attackers to access /v1/memory/stats and /v1/memory/counts because they omit the require_auth dependency. Attackers can bypass the configured DOCLING_SERVE_API_KEY to read process and cgroup memory telemetry, object type histograms, and force repeated gc.collect() heap enumeration.
Published: 2026-10-11
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Data Exposure
Action: Patch Promptly
AI Analysis

Impact

docling-serve provides PDF and document services through an HTTP API. In releases 1.14.0 through 1.36.0 the endpoints /v1/memory/stats and /v1/memory/counts incorrectly omit the authentication guard, allowing anyone to request memory telemetry, object type histograms, and trigger repeated GC collection. This missing authentication (CWE‑306) exposes sensitive runtime information and can facilitate denial‑of‑service actions by overloading the memory collection routine.

Affected Systems

Vulnerable deployments are those running any docling-serve release from 1.14.0 up to 1.36.0 and exposing the memory endpoints to any network that can reach them. The issue exists in the open‑source project maintained by the docling‑project; no other vendor variants are listed.

Risk and Exploitability

The CVSS base score of 6.3 indicates moderate severity, affecting confidentiality and integrity when an attacker obtains the memory data. EPSS is not available, so precise exploitation probability is unknown, and the vulnerability is not included in CISA’s KEV catalog. An attacker can exploit the flaw over the network by issuing unauthenticated HTTP requests to the /v1/memory/stats and /v1/memory/counts endpoints, thereby bypassing the DOCLING_SERVE_API_KEY enforcement. This inference is based on the documented omission of the authentication dependency.

Generated by OpenCVE AI on October 11, 2026 at 13:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest docling-serve release that restores authentication on the memory endpoints (any version newer than 1.36.0 that includes the fix).
  • If an upgrade is not possible immediately, block or restrict access to /v1/memory/stats and /v1/memory/counts using firewall rules, API gateway controls, or a reverse‑proxy authentication layer.
  • Ensure the DOCLING_SERVE_API_KEY configuration is set and enforce it on all public endpoints, and modify the code to require authentication on the affected memory routes.

Generated by OpenCVE AI on October 11, 2026 at 13:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description docling-serve 1.14.0 through 1.36.0 contains a missing authentication vulnerability that allows unauthenticated attackers to access /v1/memory/stats and /v1/memory/counts because they omit the require_auth dependency. Attackers can bypass the configured DOCLING_SERVE_API_KEY to read process and cgroup memory telemetry, object type histograms, and force repeated gc.collect() heap enumeration.
Title docling-serve 1.14.0 through 1.36.0 Missing Authentication via Memory Management Endpoints
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:49.965Z

Reserved: 2026-10-11T01:53:24.755Z

Link: CVE-2026-108749

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:19.670

Modified: 2026-10-11T13:17:19.670

Link: CVE-2026-108749

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T14:00:18Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function