MediumVulnerability
CVE-2026-105749: Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-105749
- Published
- Record updated
Summary
Docling, a document-parsing library with generative AI integrations, has a resource exhaustion flaw in its HTML, JATS, OpenDocument spreadsheet, and BoxNote backends (docling/backend/html_backend.py, docling/backend/jats_backend.py, docling/backend/boxnote_backend.py) in versions 2.0.0 through 2.131.0. These backends accept unbounded rowspan and colspan values and allocate a table grid proportional to the declared span, so a very small document can cause sustained CPU use or multi-gigabyte memory allocation. The document_timeout setting does not interrupt the single backend conversion call, and exporting through TableData.grid can materialize the oversized grid.
Mitigation
This issue is fixed in 2.131.0.
Related items
- MediumGHSA-v36g-jcw9-x7cw: Pydantic AI: Excessive resource use when local web fetching converts nested HTMLSimilar attack · GitHub Advisory Database
- MediumGHSA-v2xh-2vp8-57h8: Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrlSimilar attack · GitHub Advisory Database
- MediumGHSA-fpf4-vwcp-v4hp: Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch`Similar attack · GitHub Advisory Database
- HighCVE-2026-107286: Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 2.10.0 until…Similar attack · NVD/CVE Database
- MediumPoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining BotnetSimilar attack · The Hacker News