{"data":{"id":"cb3ae136-6692-4d02-9b62-08bde0ca28e1","title":"CVE-2026-105749: Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI…","summary":"Docling, a document-parsing library with generative AI integrations, has a resource exhaustion flaw in its HTML, JATS, OpenDocument spreadsheet, and BoxNote backends (docling/backend/html_backend.py, docling/backend/jats_backend.py, docling/backend/boxnote_backend.py) in versions 2.0.0 through 2.131.0. These backends accept unbounded rowspan and colspan values and allocate a table grid proportional to the declared span, so a very small document can cause sustained CPU use or multi-gigabyte memory allocation. The document_timeout setting does not interrupt the single backend conversion call, and exporting through TableData.grid can materialize the oversized grid.","solution":"This issue is fixed in 2.131.0.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105749","publishedAt":"2026-10-05T22:16:57.943Z","cveId":"CVE-2026-105749","cweIds":["CWE-400","CWE-789"],"cvssScore":"6.5","cvssSeverity":"medium","severity":"medium","attackType":["denial_of_service"],"issueType":"vulnerability","affectedPackages":["docling@>= 2.0.0, < 2.131.0 (fixed: 2.131.0)","docling-slim@>= 2.92.0, < 2.131.0 (fixed: 2.131.0)"],"affectedPackageNames":["docling","docling-slim"],"affectedVendors":[],"affectedVendorsRaw":["Docling"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":"Docling resource exhaustion via unbounded table span attributes","headlinePromptVersion":"h1","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"required","exploitMaturity":"unknown","epssScore":0.00266,"epssCheckedAt":"2026-10-10T02:57:23.167Z","kevDateAdded":null,"advisoryAliases":["GHSA-cgc7-9qp3-86m3"],"affectedPackagesSource":"ghsa","affectedPackagesCheckedAt":"2026-10-10T03:42:52.544Z","patchAvailable":true,"disclosureDate":"2026-10-05T22:16:57.943Z","capecIds":["CAPEC-125","CAPEC-130"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":"rag","llmSpecific":false,"classifierConfidence":0.8,"researchCategory":null,"atlasIds":null}}