CVE-2026-108749
Received Received - Intake

Unauthenticated Memory Stats Access in Docling-Serve

Vulnerability report for CVE-2026-108749, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

docling-serve 1.14.0 through 1.36.0 contains a missing authentication vulnerability that allows unauthenticated attackers to access /v1/memory/stats and /v1/memory/counts because they omit the require_auth dependency. Attackers can bypass the configured DOCLING_SERVE_API_KEY to read process and cgroup memory telemetry, object type histograms, and force repeated gc.collect() heap enumeration.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
docling-project docling-serve 1.14.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-108749 is a missing authentication vulnerability in docling-serve versions 1.14.0 through 1.36.0. It allows unauthenticated attackers to access memory management endpoints /v1/memory/stats and /v1/memory/counts by bypassing the required API key authentication. These endpoints expose process and cgroup memory telemetry, object type histograms, and garbage collection data without proper access control.

Detection Guidance

Check if the affected endpoints /v1/memory/stats and /v1/memory/counts are accessible without an API key. Use curl commands like: curl -X GET http://<target>/v1/memory/stats and curl -X GET http://<target>/v1/memory/counts. If these return data without requiring the X-Api-Key header, the system is vulnerable.

Impact Analysis

This vulnerability allows attackers to read sensitive memory telemetry data and repeatedly trigger garbage collection heap enumeration. While it does not expose document content or secrets, it could provide operational insights that might aid in further attacks. The impact is limited to operational telemetry exposure and potential performance degradation from forced garbage collection.

Compliance Impact

The vulnerability exposes operational telemetry data such as memory usage and garbage collection metrics. While not directly accessing sensitive user data, it could indirectly aid in reconnaissance for further attacks. GDPR and HIPAA primarily focus on protecting personal and health data, so this issue does not directly violate these regulations. However, unauthorized access to system metrics may conflict with organizational security policies and compliance frameworks requiring strict access controls.

Mitigation Strategies

Upgrade docling-serve to a version beyond 1.36.0 where the issue is fixed. If upgrading is not possible, disable the management endpoints by setting DOCLING_SERVE_ENABLE_MANAGEMENT_ENDPOINTS=false. Ensure API key authentication is enforced for all endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108749. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart