Skip to content
MediumVulnerability

CVE-2026-105747: Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI…

Identifier
CVE-2026-105747
Published
Record updated
View JSON

Summary

Docling, a document processing library, versions 2.45.0 through 2.131.0, calls tarfile.TarFile.getmembers() in METS-GBS format detection (docling/datamodel/document.py) and in docling/backend/mets_gbs_backend.py before max_member_count is enforced. A small gzip-compressed tar with a very large number of empty members can therefore consume memory proportional to its declared member count, including during format detection before allowed_formats is applied. This is a residual weakness in the protection added for CVE-2026-44018.

Mitigation

Fixed in 2.131.0.