CVE-2026-105749
Received Received - Intake

Denial of Service in Docling Document Processing

Vulnerability report for CVE-2026-105749, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.0.0 until 2.131.0, the HTML, JATS, OpenDocument spreadsheet, and BoxNote backends, including docling/backend/html_backend.py, docling/backend/jats_backend.py, and docling/backend/boxnote_backend.py, accept the rowspan and colspan attribute values without an upper bound and execute loops or allocate a table grid proportional to the declared span. A very small document can therefore cause sustained CPU use or multi-gigabyte memory allocation, and the document_timeout setting does not interrupt the single backend conversion call. Export through the TableData.grid property can further materialize the oversized grid. This issue is fixed in 2.131.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
docling-project docling >= 2.0.0, < 2.131.0
docling-project docling-slim >= 2.92.0, < 2.131.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
CWE-789 The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Docling versions 2.0.0 to 2.131.0 allows malicious documents to cause excessive CPU usage or memory allocation by exploiting unbounded rowspan and colspan attributes in HTML, JATS, OpenDocument spreadsheet, and BoxNote formats. The backend processes these attributes without limits, leading to potential denial-of-service conditions.

Detection Guidance

The vulnerability involves excessive CPU or memory usage due to unbounded rowspan and colspan attributes in documents processed by Docling versions 2.0.0 to 2.131.0. To detect it, monitor system resources during document processing. Check for processes consuming unusually high CPU or memory when Docling handles HTML, JATS, OpenDocument spreadsheet, or BoxNote files. Use system monitoring tools like top, htop, or ps to observe resource usage. If Docling is running in a container, check resource limits and logs for abnormal behavior.

Impact Analysis

An attacker could craft a small document with extreme rowspan or colspan values to consume excessive system resources during processing. This may cause application slowdowns, crashes, or system instability. The vulnerability persists even with document_timeout settings since backend conversion calls are not interrupted.

Compliance Impact

This vulnerability could lead to denial-of-service conditions due to excessive CPU or memory usage, potentially disrupting services handling sensitive data. For GDPR, this may impact availability of personal data processing systems. For HIPAA, it could affect the integrity and availability of protected health information systems.

Mitigation Strategies

Upgrade Docling to version 2.131.0 or later to address the vulnerability. If upgrading is not immediately possible, restrict document processing to trusted sources and limit file sizes. Disable or monitor the TableData.grid export feature to prevent memory exhaustion. Apply resource limits on Docling processes to cap CPU and memory usage. Review and update firewall or network policies to block suspicious documents.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105749. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart