DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-105749: CVE-2026-105749: Unbounded Table Attributes in Docling Backends Leads to Resource Exhaustion

CVE-2026-105749: Unbounded Table Attributes in Docling Backends Leads to Resource Exhaustion

Vulnerability ID: CVE-2026-105749
CVSS Score: 6.5
Published: 2026-10-07

An uncontrolled resource consumption vulnerability exists in the Docling document conversion library. Maliciously structured HTML, JATS, ODS, or BoxNote inputs containing table cells with excessively large 'rowspan' or 'colspan' attribute values trigger algorithmic complexity conditions. This allows unauthenticated remote attackers to initiate resource exhaustion states, crashing or hanging the target document processing pipeline while bypassing configured timeouts.

TL;DR

Docling document parsers lack validation checks for table row and column spans, allowing tiny documents with extreme span values to exhaust host memory and CPU resources.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-400 (Uncontrolled Resource Consumption)
  • Attack Vector: Network / Remote Document Ingestion
  • CVSS Severity: 6.5 (Medium)
  • EPSS Score: 0.00256 (Percentile: 15.73%)
  • Impact: Complete Application Hang or Out-of-Memory Crash
  • Exploit Status: Proof-of-Concept Available
  • KEV Status: Not Listed

Affected Systems

  • Docling (Python Package)
  • Docling-Slim (Python Package)
  • Document Parsing Microservices utilizing Docling
  • docling: >= 2.0.0, < 2.131.0 (Fixed in: 2.131.0)
  • docling-slim: >= 2.92.0, < 2.131.0 (Fixed in: 2.131.0)

Code Analysis

Commit: c5b4429

Add table span checks in HTML, JATS XML, ODS, and BoxNote parsing backends to clamp attributes to safe maximum limits.

Mitigation Strategies

  • Upgrade Docling packages to version 2.131.0 or higher.
  • Implement proactive file scanning and regex filtering on upload endpoints to reject anomalous table span definitions.
  • Isolate parsing workloads within memory-limited sandbox environments (e.g., Docker containers with tight cgroups configuration).

Remediation Steps:

  1. Run 'pip install --upgrade docling' to update your environment to version 2.131.0.
  2. Confirm that the sub-dependency 'docling-core' is updated to at least version 2.98.0.
  3. Deploy static analysis or payload validation on files prior to parsing to drop any documents containing unreasonably long strings within table attributes.

References


Read the full report for CVE-2026-105749 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)