Vulnerability Description
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend's XML parsing and the input document format detection lacked security controls. An attacker could craft malicious METS-GBS archives that, when processed, could read sensitive files, exhaust system resources, or cause application crashes. This vulnerability is fixed in 2.91.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Docling | Docling | >= 2.45.0, < 2.91.0 |
Related Weaknesses (CWE)
References
- https://github.com/docling-project/docling/releases/tag/v2.91.0Release Notes
- https://github.com/docling-project/docling/security/advisories/GHSA-r3xg-rg9j-67PatchVendor Advisory
FAQ
What is CVE-2026-44018?
CVE-2026-44018 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend's XML parsing and the inpu...
How severe is CVE-2026-44018?
CVE-2026-44018 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-44018?
Check the references section above for vendor advisories and patch information. Affected products include: Docling Docling.