CVE-2026-105749: medium-severity vulnerability in docling-project docling
Docling: Unbounded table rowspan/colspan in HTML, JATS, ODS and BoxNote backends causes CPU/memory exhaustion
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.5epss 0.3%
exploitation probability
0.3%top 84% of all CVEs
observed exploitation
nono source reports it
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.0.0 until 2.131.0, the HTML, JATS, OpenDocument spreadsheet, and BoxNote backends, including docling/backend/html_backend.py, docling/backend/jats_backend.py, and docling/backend/boxnote_backend.py, accept the rowspan and colspan attribute values without an upper bound and execute loops or allocate a table grid proportional to the declared span. A very small document can therefore cause sustained CPU use or multi-gigabyte memory allocation, and the document_timeout setting does not interrupt the single backend conversion call. Export through the TableData.grid property can further materialize the oversized grid. This issue is fixed in 2.131.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Related CVEs — docling-project docling
In the same product, most dangerous first.
CVE-2026-44017HIGHDocling: Unsafe Zip Extraction in EasyOCR Model DownloadEPSS 0.7%CVE-2026-44020HIGHDocling: Unsafe XML Entity Expansion in USPTO Patent BackendEPSS 0.6%CVE-2026-44016HIGHDocling: Unsafe Playwright-based HTML RenderingEPSS 0.6%CVE-2026-47214HIGHDocling: Unsafe URI and Path Handling in HTML BackendEPSS 0.4%CVE-2026-105751MEDIUMDocling: Arbitrary local file read via draw:image xlink:href in the OpenDocument backendEPSS 0.4%CVE-2026-105744HIGHDocling: Arbitrary file read/write (and command execution when shell-escape is enabled) when rendering untrusted TikZ with the opt-in Tectonic engineEPSS 0.3%