Resource Exhaustion Vulnerability in Docling Document Processing Tool
CVE-2026-105749

6.5MEDIUM

Key Information:

Vendor
CVE Published:
5 October 2026

What is CVE-2026-105749?

Docling, a document processing tool, features a vulnerability that allows for resource exhaustion through its HTML, JATS, OpenDocument spreadsheet, and BoxNote backends. Versions 2.0.0 to 2.131.0 are susceptible as they accept rowspan and colspan attribute values without limits. When exploited, even small documents can trigger significant CPU consumption or excessive memory allocation. The document_timeout setting fails to halt backend processes, leading to potential system slowdowns and instability. This issue was addressed in version 2.131.0, providing an essential update for users.

Affected Version(s)

docling >= 2.0.0, < 2.131.0

docling-slim >= 2.92.0, < 2.131.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.