MediumVulnerability
GHSA-f4ch-vxwc-3p2m: Duplicate Advisory: Docling: METS-GBS archive member limit enforced after full member enumeration (memory exhaustion during format detection)
- Identifier
- GHSA-f4ch-vxwc-3p2m
- Published
- Record updated
Summary
This advisory was withdrawn as a duplicate of GHSA-3cr3-8m4c-fpxw and is kept for external references. The original description says Docling from 2.45.0 through 2.131.0 calls tarfile.TarFile.getmembers() in the METS-GBS format detection and backend before enforcing max_member_count, so a small gzip-compressed tar with a very large number of empty members can consume memory proportional to the declared member count. The flaw is a residual weakness in the protection added for CVE-2026-44018.
Mitigation
Fixed in 2.131.0.
Related items
- MediumGHSA-v36g-jcw9-x7cw: Pydantic AI: Excessive resource use when local web fetching converts nested HTMLSimilar attack · GitHub Advisory Database
- MediumGHSA-v2xh-2vp8-57h8: Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrlSimilar attack · GitHub Advisory Database
- MediumGHSA-fpf4-vwcp-v4hp: Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch`Similar attack · GitHub Advisory Database
- HighCVE-2026-107286: Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 2.10.0 until…Similar attack · NVD/CVE Database
- MediumPoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining BotnetSimilar attack · The Hacker News