AI and data stack advisories

Severe, 6 weeks2973Projects319

2973 severe, 6 weeks · 319 projects

doclingGHSA-cgc7-9qp3-86m3

Docling: Unbounded table rowspan/colspan in HTML, JATS, ODS and BoxNote backends causes CPU/memory exhaustion

docling

CVE-2026-105749 · Published Oct 7, 2026

Medium6.5
Fix: upgrade to 2.131.0 or later
GitHub advisory

Summary

The HTML, JATS, ODS (OpenDocument spreadsheet) and BoxNote backends accept table rowspan / colspan values without an upper bound. A few bytes of input, such as <td rowspan="100000000">, make docling run loops proportional to the declared span and allocate a table grid of the declared size. The result is CPU and memory exhaustion.

Details

  • docling/backend/html_backend.py (_get_cell_spans) parses span attributes with no upper limit. The cell-filling loop then iterates row_span × col_span times.
  • docling/backend/jats_backend.py and docling/backend/boxnote_backend.py fill their tables the same way.
  • The OpenDocument spreadsheet path scans the declared span range.
  • Export (for example export_to_markdown()) materialises the full grid through TableData.grid in docling-core.

document_timeout does not bound this. It is checked between pipeline stages, and these backends convert the whole document in a single call. max_file_size and max_num_pages do not help because the payload is tiny.

Measured on 2.130.0: a 54-byte HTML file with rowspan="1e8" takes about 4.4 s of CPU, and the time grows linearly with the value. A 52-byte file with colspan="3000000" takes about 23 s and reaches 4.5 GB peak memory during Markdown export.

Impact

Denial of service of the converting process from a very small input document. Confidentiality and...

Affected versions

PackageAffectedFixed in
docling
PyPI
>= 2.0.0, < 2.131.02.131.0
Details and references

### Summary The HTML, JATS, ODS (OpenDocument spreadsheet) and BoxNote backends accept table `rowspan` / `colspan` values without an upper bound. A few bytes of input, such as `<td rowspan="100000000">`, make docling run loops proportional to the declared span and allocate a table grid of the declared size. The result is CPU and memory exhaustion. ### Details - `docling/backend/html_backend.py` (`_get_cell_spans`) parses span attributes with no upper limit. The cell-filling loop then iterates `row_span × col_span` times. - `docling/backend/jats_backend.py` and `docling/backend/boxnote_backend.py` fill their tables the same way. - The OpenDocument spreadsheet path scans the declared span range. - Export (for example `export_to_markdown()`) materialises the full grid through `TableData.grid` in docling-core. `document_timeout` does not bound this. It is checked between pipeline stages, and these backends convert the whole document in a single call. `max_file_size` and `max_num_pages` do not help because the payload is tiny. Measured on 2.130.0: a 54-byte HTML file with `rowspan="1e8"` takes about 4.4 s of CPU, and the time grows linearly with the value. A 52-byte file with `colspan="3000000"` takes about 23 s and reaches 4.5 GB peak memory during Markdown export. ### Impact Denial of service of the converting process from a very small input document. Confidentiality and integrity are not affected. ### Proof of concept ```html <table><tr><td colspan="3000000">x</td></tr></table> ``` ```python from docling.document_converter import DocumentConverter DocumentConverter().convert("span.html").document.export_to_markdown() ``` ### Patches Fixed in docling 2.131.0 by [#4414](https://github.com/docling-project/docling/pull/4414). Table spans are clamped to the HTML limits (colspan 1000, rowspan 65534) and to the actual size of the table in the HTML, JATS, BoxNote and OpenDocument spreadsheet backends, so conversion time and memory grow with the real table only. ### Workarounds Upgrade to 2.131.0. For older versions: Run conversions of untrusted documents in a separate process with memory and CPU-time limits, or restrict `allowed_formats` to formats that are not affected.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-400, CWE-789
Also known as
CVE-2026-105749

More docling advisories

All docling
Advisory
Docling: Configured HTTP headers sent to every remote image host named by a document
Low3.7Oct 7
docling: race condition
Medium4.0Oct 7
docling: insecure default
High7.5Oct 7
Docling: Crafted DoclingDocument JSON embeds local image files into converted output
Medium4.3Oct 7
Docling imports plugin entry points before the allow_external_plugins check
Medium6.7Oct 7
docling: resource exhaustion
Medium4.3Oct 6