id: PYSEC-2026-2144 published: "2026-06-26T16:16:30.767Z" modified: "2026-07-13T05:48:35.499256Z" aliases: - CVE-2026-44018 - GHSA-r3xg-rg9j-67fv details: Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend's XML parsing and the input document format detection lacked security controls. An attacker could craft malicious METS-GBS archives that, when processed, could read sensitive files, exhaust system resources, or cause application crashes. This vulnerability is fixed in 2.91.0. affected: - package: name: docling ecosystem: PyPI purl: pkg:pypi/docling ranges: - type: ECOSYSTEM events: - introduced: 2.45.0 - fixed: 2.91.0 versions: - 2.45.0 - 2.46.0 - 2.47.0 - 2.47.1 - 2.48.0 - 2.49.0 - 2.50.0 - 2.51.0 - 2.52.0 - 2.53.0 - 2.54.0 - 2.55.0 - 2.55.1 - 2.56.0 - 2.56.1 - 2.57.0 - 2.58.0 - 2.59.0 - 2.60.0 - 2.60.1 - 2.61.0 - 2.61.1 - 2.61.2 - 2.62.0 - 2.63.0 - 2.64.0 - 2.64.1 - 2.65.0 - 2.66.0 - 2.67.0 - 2.68.0 - 2.69.0 - 2.69.1 - 2.70.0 - 2.71.0 - 2.72.0 - 2.73.0 - 2.73.1 - 2.74.0 - 2.75.0 - 2.76.0 - 2.77.0 - 2.78.0 - 2.79.0 - 2.80.0 - 2.81.0 - 2.82.0 - 2.83.0 - 2.84.0 - 2.85.0 - 2.86.0 - 2.87.0 - 2.88.0 - 2.89.0 - 2.90.0 ecosystem_specific: {} references: - type: ADVISORY url: https://github.com/docling-project/docling/releases/tag/v2.91.0 - type: FIX url: https://github.com/docling-project/docling/security/advisories/GHSA-r3xg-rg9j-67fv severity: - type: CVSS_V3 score: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H