Skip to content
MediumVulnerability

CVE-2026-105749: Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI…

Identifier
CVE-2026-105749
Published
Record updated
View JSON

Summary

Docling, a document-parsing library with generative AI integrations, has a resource exhaustion flaw in its HTML, JATS, OpenDocument spreadsheet, and BoxNote backends (docling/backend/html_backend.py, docling/backend/jats_backend.py, docling/backend/boxnote_backend.py) in versions 2.0.0 through 2.131.0. These backends accept unbounded rowspan and colspan values and allocate a table grid proportional to the declared span, so a very small document can cause sustained CPU use or multi-gigabyte memory allocation. The document_timeout setting does not interrupt the single backend conversion call, and exporting through TableData.grid can materialize the oversized grid.

Mitigation

This issue is fixed in 2.131.0.