Memory Consumption Vulnerability in Docling by Docling Project
CVE-2026-105747
What is CVE-2026-105747?
Docling, a tool designed for simplifying document processing through the parsing of various formats, has a vulnerability affecting versions from 2.45.0 to 2.131.0. This issue arises from a flaw in the METS-GBS format detection code, where the method for retrieving members from a tar file does not adequately enforce a maximum member count before processing. As a result, when faced with a gzip-compressed tar archive that contains many empty members, the application can allocate memory proportional to the number of declared members, potentially leading to memory exhaustion during format detection. This vulnerability is a continuation of weaknesses previously addressed in related security improvements and can be mitigated by upgrading to version 2.131.0.
Affected Version(s)
docling >= 2.45.0, < 2.131.0
docling-slim >= 2.45.0, < 2.131.0
