Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105747— Docling: METS-GBS archive member limit enforced after full member enumeration (memory exhaustion during format detection)

Quick assessment

Affected
docling-project docling
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Docling 通过解析多种文档格式并提供与生成式 AI 生态系统的集成,简化了文档处理流程。在版本 2.45.0 至 2.131.0 之间, 中的 METS-GBS 格式检测机制以及 中的后端组件,在强制实施最大成员数量(max_member_count)限制之前,会先调用 。这导致在处理流程被该限制中断之前,整个归档文件的成员列表已被完全加载到内存中。 因此,一个包含大量空条目的小型 gzip 压缩 tar 归档文件,可能消耗与声明的成员数量成比例的内存空间,甚至在应用 限制之前(即格式检测阶段)也会发生这种情

CVSS 4.3 · Medium

Possible ATT&CK Techniques 1 AI

T1133 · External Remote Services
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105747

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Docling: METS-GBS archive member limit enforced after full member enumeration (memory exhaustion during format detection)
Source: CVE Program / CVE List V5
Vulnerability Description
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.131.0, METS-GBS format detection in docling/datamodel/document.py and the backend in docling/backend/mets_gbs_backend.py call tarfile.TarFile.getmembers() before enforcing the max_member_count limit, causing the full archive member list to be allocated before the limit can stop processing. A small gzip-compressed tar archive with a very large number of empty members can therefore consume memory proportional to the declared member count, including during format detection before the allowed_formats restriction is applied. This issue is a residual weakness in the member-count protection added for CVE-2026-44018. This issue is fixed in 2.131.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
对高度压缩数据的处理不恰当(数据放大攻击)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
docling-project docling >= 2.45.0, < 2.131.0 -
docling-project docling-slim >= 2.45.0, < 2.131.0 -

II. Public POCs for CVE-2026-105747

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105747

请登录查看更多情报信息。

Other References for CVE-2026-105747 (4)

Same Patch Batch · docling-project · 2026-10-05 · 10 CVEs total

CVE-2026-105744 7.5 HIGH Docling: Arbitrary file read/write (and command execution when shell-escape is enabled) wh
CVE-2026-105751 6.9 MEDIUM Docling: Arbitrary local file read via draw:image xlink:href in the OpenDocument backend
CVE-2026-105745 6.7 MEDIUM Docling: Plugin entry points are imported before the allow_external_plugins check
CVE-2026-105749 6.5 MEDIUM Docling: Unbounded table rowspan/colspan in HTML, JATS, ODS and BoxNote backends causes CP
CVE-2026-105750 5.9 MEDIUM Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode
CVE-2026-105748 4.3 MEDIUM Docling: Crafted DoclingDocument JSON embeds local image files into converted output
CVE-2026-105743 4.0 MEDIUM Docling: SSRF guard bypass in remote resource fetching (DNS rebinding / multi-record resol
CVE-2026-105742 3.7 LOW Docling: Configured HTTP headers sent to every remote image host named by a document
CVE-2026-105746 2.2 LOW Docling: KServe v2 OCR engine does not enforce enable_remote_services

IV. Related Vulnerabilities

V. Comments for CVE-2026-105747

No comments yet


Leave a comment