Skip to content
doclingGHSA-9f4q-q82q-4359

Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks

High7.5CVE-2026-31248 · Published May 11, 2026 · updated Jul 13, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
docling
PyPI
<= 2.61.0No fix yet
Details and references

Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend extracts and validates XML files from .tar.gz archives using etree.fromstring() without disabling entity resolution. An attacker can craft a malicious XML file with nested entity definitions (XML Bomb) and package it into a .tar.gz archive. When processed by Docling, the exponential expansion of entities during XML parsing leads to excessive resource consumption, resulting in a denial of service (DoS) condition on the system running the Docling parser.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-776
Also known as
CVE-2026-31248, PYSEC-2026-2454

More docling advisories

All
DateAdvisory
May 11Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks
CVE-2026-31247High7.5no fix yet
Jun 3Docling: Unsafe Zip Extraction in EasyOCR Model Download
CVE-2026-44017High7.5fixed in 2.91.0
Jun 3Docling: Unsafe Playwright-based HTML Rendering
CVE-2026-44016High8.2fixed in 2.91.0
Jun 3Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend
CVE-2026-44018Medium5.5fixed in 2.91.0
Jun 3Docling: Unsafe XML Entity Expansion in USPTO Patent Backend
CVE-2026-44020High7.5fixed in 2.74.0
Jun 3Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands
CVE-2026-44022Medium5.5fixed in 2.91.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.