CVE-2026-105749: Unbounded Table Attributes in Docling Backends Leads to Resource Exhaustion
Vulnerability ID: CVE-2026-105749
CVSS Score: 6.5
Published: 2026-10-07
An uncontrolled resource consumption vulnerability exists in the Docling document conversion library. Maliciously structured HTML, JATS, ODS, or BoxNote inputs containing table cells with excessively large 'rowspan' or 'colspan' attribute values trigger algorithmic complexity conditions. This allows unauthenticated remote attackers to initiate resource exhaustion states, crashing or hanging the target document processing pipeline while bypassing configured timeouts.
TL;DR
Docling document parsers lack validation checks for table row and column spans, allowing tiny documents with extreme span values to exhaust host memory and CPU resources.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-400 (Uncontrolled Resource Consumption)
- Attack Vector: Network / Remote Document Ingestion
- CVSS Severity: 6.5 (Medium)
- EPSS Score: 0.00256 (Percentile: 15.73%)
- Impact: Complete Application Hang or Out-of-Memory Crash
- Exploit Status: Proof-of-Concept Available
- KEV Status: Not Listed
Affected Systems
- Docling (Python Package)
- Docling-Slim (Python Package)
- Document Parsing Microservices utilizing Docling
-
docling: >= 2.0.0, < 2.131.0 (Fixed in:
2.131.0) -
docling-slim: >= 2.92.0, < 2.131.0 (Fixed in:
2.131.0)
Code Analysis
Commit: c5b4429
Add table span checks in HTML, JATS XML, ODS, and BoxNote parsing backends to clamp attributes to safe maximum limits.
Mitigation Strategies
- Upgrade Docling packages to version 2.131.0 or higher.
- Implement proactive file scanning and regex filtering on upload endpoints to reject anomalous table span definitions.
- Isolate parsing workloads within memory-limited sandbox environments (e.g., Docker containers with tight cgroups configuration).
Remediation Steps:
- Run 'pip install --upgrade docling' to update your environment to version 2.131.0.
- Confirm that the sub-dependency 'docling-core' is updated to at least version 2.98.0.
- Deploy static analysis or payload validation on files prior to parsing to drop any documents containing unreasonably long strings within table attributes.
References
- Docling Advisory (GHSA-cgc7-9qp3-86m3)
- NVD CVE Record
- CVE.org Record
- Fix Commit
- Fix Pull Request
- Docling Release Tag v2.131.0
Read the full report for CVE-2026-105749 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)