Sceawere

Vulnerability Detail

CVE-2026-105747UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Docling Unbounded Resource Allocation Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
1h ago
Vendor
docling-project
Product
docling
Attack Type
CWE-409: Improper Handling of Highly Compressed Data (Data Amplification)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.131.0, METS-GBS format detection in docling/datamodel/document.py and the backend in docling/backend/mets_gbs_backend.py call tarfile.TarFile.getmembers() before enforcing the max_member_count limit, causing the full archive member list to be allocated before the limit can stop processing. A small gzip-compressed tar archive with a very large number of empty members can therefore consume memory proportional to the declared member count, including during format detection before the allowed_formats restriction is applied. This issue is a residual weakness in the member-count protection added for CVE-2026-44018. This issue is fixed in 2.131.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-05T22:16:57.633Z",
  "pubdate": "2026-10-05T22:16:57.633Z",
  "executiveSummary": "Docling, a document processing library, contains a resource exhaustion vulnerability within its METS-GBS format handling logic. The vulnerability resides in the premature invocation of tarfile.TarFile.getmembers() during initial format detection, which occurs prior to the enforcement of safety limits such as max_member_count. This flaw allows an attacker to trigger significant memory consumption by submitting a maliciously crafted, highly compressed tar archive containing an excessive number of empty members. The issue acts as a residual weakness following previous security patches (CVE-2026-44018). Successful exploitation results in a Denial of Service (DoS) condition, as the application allocates memory proportional to the declared member count before validation checks can terminate the processing of the archive. This vulnerability affects Docling versions 2.45.0 through 2.130.0 and does not require authentication to exploit if the application accepts external document uploads.\nThe risk is categorized as high for services that automatically process document uploads, as the memory exhaustion is triggered during the early format identification phase, effectively bypassing existing document processing limits.",
  "technicalDetails": "The vulnerability is located within the METS-GBS format detection workflow, specifically involving docling/datamodel/document.py and the backend logic in docling/backend/mets_gbs_backend.py. The root cause is an improper sequencing of security operations: the system invokes tarfile.TarFile.getmembers() on an untrusted tar archive as part of the format identification process before the established max_member_count safety threshold is enforced.\nIn Python's tarfile module, calling .getmembers() forces the parser to read and parse the entire header metadata of the tar archive to populate the member list. Because this occurs before the application logic applies its internal allowed_formats restrictions or member count limits, an attacker can supply a specially crafted gzip-compressed tar archive designed to appear small in physical file size but containing a massive number of archive members (e.g., millions of empty files).\nThe attack flow is as follows: 1. An attacker submits a malicious archive to the document ingestion pipeline. 2. Docling initiates the format detection process to determine the document type. 3. The METS-GBS backend logic calls tarfile.TarFile.getmembers(), which parses the entire archive metadata into memory. 4. Due to the high density of members in the malicious payload, the system allocates excessive memory to represent these objects. 5. The application's memory usage spikes, leading to a heap exhaustion or system-wide resource contention. 6. By the time the code reaches the max_member_count validation logic, the memory footprint has already been significantly impacted, or the process has been terminated by the operating system OOM (Out of Memory) killer.\nThis vulnerability is considered a residual weakness of the protection mechanisms introduced for CVE-2026-44018. The existing guardrails fail to secure the early-stage format sniffing process, rendering the protections ineffective against this specific attack vector. Exploitation does not require authentication or elevated privileges, provided the target system's input path exposes the METS-GBS parser to external data."
}
CVE-2026-105747: Docling Unbounded Resource Allocation Vulnerability (MEDIUM Severity, CVSS: 4.3) | Sceawere